mirror of
https://github.com/kernelkit/infix.git
synced 2026-07-27 11:13:02 +02:00
Compare commits
145
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1854bca98b | ||
|
|
00261fb120 | ||
|
|
4a69d1564d | ||
|
|
0c917ab37e | ||
|
|
8c9c432847 | ||
|
|
635acd504f | ||
|
|
204e681b3a | ||
|
|
4f40db6ee8 | ||
|
|
82236b7f5a | ||
|
|
5e9975f4c9 | ||
|
|
d3e653d480 | ||
|
|
e06bcb64a5 | ||
|
|
c5015faafe | ||
|
|
76cf464a01 | ||
|
|
e5e97719e8 | ||
|
|
9605252be8 | ||
|
|
34fa6a327d | ||
|
|
551f1ae548 | ||
|
|
76c8c69231 | ||
|
|
4ad2948b9b | ||
|
|
0c0b7f0532 | ||
|
|
4ae641d65f | ||
|
|
da67ea3695 | ||
|
|
8bf78c2fbb | ||
|
|
b3bb8a3075 | ||
|
|
fdf3056a93 | ||
|
|
6bf1c346d7 | ||
|
|
4acfec3d41 | ||
|
|
acef9aecde | ||
|
|
e18ddcf0c8 | ||
|
|
efec5f57cd | ||
|
|
fc7d9bacac | ||
|
|
874873e727 | ||
|
|
28cf5525bf | ||
|
|
d1fe3b1311 | ||
|
|
b33294950f | ||
|
|
92d3db46a7 | ||
|
|
5d128d74f5 | ||
|
|
d2b370b44d | ||
|
|
eef60de999 | ||
|
|
83d18eb988 | ||
|
|
64d63c08df | ||
|
|
282e7b08a3 | ||
|
|
bff0417be8 | ||
|
|
c1836af7cc | ||
|
|
1a99118a78 | ||
|
|
c3e3a58af0 | ||
|
|
280190ac24 | ||
|
|
e612014662 | ||
|
|
a4a1673f0f | ||
|
|
c4d436a2fd | ||
|
|
985a76c567 | ||
|
|
5ac7899f37 | ||
|
|
1a5224481d | ||
|
|
5653f298df | ||
|
|
140379190c | ||
|
|
c182fd43a8 | ||
|
|
b55f74395b | ||
|
|
493be97769 | ||
|
|
d34e852574 | ||
|
|
14418725f4 | ||
|
|
bb498043e4 | ||
|
|
a313ea354c | ||
|
|
ab777333dc | ||
|
|
b5103b216e | ||
|
|
9b7c977c82 | ||
|
|
014eb0a98e | ||
|
|
512da8c3f3 | ||
|
|
cc8221a22a | ||
|
|
50359b0808 | ||
|
|
daa57a8a69 | ||
|
|
a48edc74d8 | ||
|
|
c7e8b8f33d | ||
|
|
4f6b810cc2 | ||
|
|
1caedbfe6f | ||
|
|
f6f52bcf16 | ||
|
|
6a84f334db | ||
|
|
320410b950 | ||
|
|
c72bc34df1 | ||
|
|
f9e9822b52 | ||
|
|
b350483617 | ||
|
|
84c32ac435 | ||
|
|
3d376dc57f | ||
|
|
81745a1625 | ||
|
|
c7ab09cb73 | ||
|
|
080dc6b591 | ||
|
|
e32334cc4a | ||
|
|
3c75608839 | ||
|
|
1dcbea52b9 | ||
|
|
1baa1c5716 | ||
|
|
34203db00a | ||
|
|
f47da7c249 | ||
|
|
817ec4675b | ||
|
|
d86374e8fa | ||
|
|
cb0fdc0ab4 | ||
|
|
7828636dd7 | ||
|
|
3611d881ff | ||
|
|
05af71eafe | ||
|
|
596edd23aa | ||
|
|
761fae8d03 | ||
|
|
84c28aab00 | ||
|
|
528671c4cd | ||
|
|
814d5f6a4d | ||
|
|
efc4ea20d6 | ||
|
|
d112f0bb29 | ||
|
|
b400a6aaa9 | ||
|
|
24ce5cbc62 | ||
|
|
ae86473675 | ||
|
|
ea3bfda2de | ||
|
|
fad75575e4 | ||
|
|
da56c95930 | ||
|
|
ea956026da | ||
|
|
9575e03dc9 | ||
|
|
dd5ace4d3f | ||
|
|
74dd8d3644 | ||
|
|
431805c1cd | ||
|
|
662719a47f | ||
|
|
3a73ce3cfb | ||
|
|
7574ad864d | ||
|
|
c9d4105d85 | ||
|
|
b6d661e40b | ||
|
|
12ab32c9d2 | ||
|
|
e140d5917a | ||
|
|
c16f8890a5 | ||
|
|
793cff3d2f | ||
|
|
a4176ce4d0 | ||
|
|
3ebbd0bf4f | ||
|
|
ce2e15e4d2 | ||
|
|
29158ed2ef | ||
|
|
25d7b84bde | ||
|
|
3867db633b | ||
|
|
d9cf3adaff | ||
|
|
3f06e107f6 | ||
|
|
2b81f34fcd | ||
|
|
2eb487ebcd | ||
|
|
b2fef1585f | ||
|
|
69c2ffcc5f | ||
|
|
2bd3b508ee | ||
|
|
3a740ff049 | ||
|
|
a0f09a1c06 | ||
|
|
4b7c97083f | ||
|
|
873de8d0b7 | ||
|
|
f1b8599afb | ||
|
|
d9ffff2b5a | ||
|
|
3519f748e5 |
@@ -8,12 +8,11 @@ on:
|
||||
|
||||
jobs:
|
||||
build:
|
||||
name: Build ${{ matrix.platform }} ${{ matrix.variant }}
|
||||
name: Build Infix ${{ matrix.platform }}
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
platform: [aarch64, x86_64]
|
||||
variant: [netconf, classic]
|
||||
fail-fast: false
|
||||
steps:
|
||||
- name: Maintenance
|
||||
@@ -25,11 +24,7 @@ jobs:
|
||||
- name: Set Build Variables
|
||||
id: vars
|
||||
run: |
|
||||
if [ "${{ matrix.variant }}" = "netconf" ]; then
|
||||
target=${{ matrix.platform }}
|
||||
else
|
||||
target=${{ matrix.platform }}-${{ matrix.variant }}
|
||||
fi
|
||||
target=${{ matrix.platform }}
|
||||
echo "dir=infix-$target" >> $GITHUB_OUTPUT
|
||||
echo "tgz=infix-$target.tar.gz" >> $GITHUB_OUTPUT
|
||||
if [ "$target" = x86_64 ]; then
|
||||
@@ -41,9 +36,8 @@ jobs:
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
path: dl/
|
||||
key: dl-${{ matrix.variant }}-${{ hashFiles('.git/modules/buildroot/HEAD', 'configs/*', 'package/*/*.hash') }}
|
||||
key: dl-${{ hashFiles('.git/modules/buildroot/HEAD', 'configs/*', 'package/*/*.hash') }}
|
||||
restore-keys: |
|
||||
dl-${{ matrix.variant }}-
|
||||
dl-
|
||||
- name: Restore Cache of .ccache/
|
||||
uses: actions/cache@v4
|
||||
@@ -55,11 +49,7 @@ jobs:
|
||||
ccache-
|
||||
- name: Configure & Build
|
||||
run: |
|
||||
if [ "${{ matrix.variant }}" = "netconf" ]; then
|
||||
target=${{ matrix.platform }}_defconfig
|
||||
else
|
||||
target=${{ matrix.platform }}_${{ matrix.variant }}_defconfig
|
||||
fi
|
||||
target=${{ matrix.platform }}_defconfig
|
||||
echo "Building $target ..."
|
||||
sudo mkdir ${{ steps.vars.outputs.out }}
|
||||
sudo chown $(id -un):$(id -gn) ${{ steps.vars.outputs.out }}
|
||||
@@ -73,14 +63,14 @@ jobs:
|
||||
ln -s ${{ steps.vars.outputs.dir }} images
|
||||
tar chfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
- name: Test
|
||||
if: matrix.platform == 'x86_64' && matrix.variant == 'netconf'
|
||||
if: matrix.platform == 'x86_64'
|
||||
run: |
|
||||
export O=${{ steps.vars.outputs.out }}
|
||||
make test-qeneth
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
path: ${{ steps.vars.outputs.out }}/${{ steps.vars.outputs.tgz }}
|
||||
name: artifact-${{ matrix.variant }}-${{ matrix.platform }}
|
||||
name: artifact-${{ matrix.platform }}
|
||||
release:
|
||||
if: ${{github.repository_owner == 'kernelkit' && github.ref_name == 'main'}}
|
||||
name: Upload Latest Build
|
||||
|
||||
@@ -16,12 +16,15 @@ concurrency:
|
||||
jobs:
|
||||
build:
|
||||
name: Regression Testing
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: self-hosted
|
||||
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
submodules: 'true'
|
||||
- name: Clean up cruft ...
|
||||
run: |
|
||||
./test/env -c
|
||||
- name: Set Build Variables
|
||||
id: vars
|
||||
run: |
|
||||
|
||||
@@ -20,12 +20,11 @@ on:
|
||||
jobs:
|
||||
build:
|
||||
if: github.repository == 'kernelkit/infix' && startsWith(github.ref, 'refs/tags/')
|
||||
name: Build Infix ${{ github.ref_name }} [${{ matrix.platform }}-${{ matrix.variant }}]
|
||||
name: Build Infix ${{ github.ref_name }} [${{ matrix.platform }}]
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
platform: [aarch64, x86_64]
|
||||
variant: [netconf, classic]
|
||||
fail-fast: false
|
||||
steps:
|
||||
- name: Maintenance
|
||||
@@ -44,11 +43,7 @@ jobs:
|
||||
fi
|
||||
echo "ver=${ver}" >> $GITHUB_OUTPUT
|
||||
fver=${ver#v}
|
||||
if [ "${{ matrix.variant }}" = "netconf" ]; then
|
||||
target=${{ matrix.platform }}-${fver}
|
||||
else
|
||||
target=${{ matrix.platform }}-${{ matrix.variant }}-${fver}
|
||||
fi
|
||||
target=${{ matrix.platform }}-${fver}
|
||||
echo "dir=infix-$target" >> $GITHUB_OUTPUT
|
||||
echo "tgz=infix-$target.tar.gz" >> $GITHUB_OUTPUT
|
||||
echo "out=/mnt/x-$target" >> $GITHUB_OUTPUT
|
||||
@@ -56,9 +51,8 @@ jobs:
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
path: dl/
|
||||
key: dl-${{ matrix.variant }}-${{ hashFiles('.git/modules/buildroot/HEAD', 'configs/*', 'package/*/*.hash') }}
|
||||
key: dl-${{ hashFiles('.git/modules/buildroot/HEAD', 'configs/*', 'package/*/*.hash') }}
|
||||
restore-keys: |
|
||||
dl-${{ matrix.variant }}-
|
||||
dl-
|
||||
- name: Restore Cache of .ccache/
|
||||
uses: actions/cache@v4
|
||||
@@ -72,27 +66,29 @@ jobs:
|
||||
env:
|
||||
INFIX_RELEASE: ${{ steps.vars.outputs.ver }}
|
||||
run: |
|
||||
if [ "${{ matrix.variant }}" = "netconf" ]; then
|
||||
target=${{ matrix.platform }}_defconfig
|
||||
else
|
||||
target=${{ matrix.platform }}_${{ matrix.variant }}_defconfig
|
||||
fi
|
||||
target=${{ matrix.platform }}_defconfig
|
||||
echo "Building $target ..."
|
||||
sudo mkdir ${{ steps.vars.outputs.out }}
|
||||
sudo chown $(id -un):$(id -gn) ${{ steps.vars.outputs.out }}
|
||||
export O=${{ steps.vars.outputs.out }}
|
||||
make $target
|
||||
make
|
||||
- name: Prepare Artifact
|
||||
- name: Generate SBOM from Build
|
||||
run: |
|
||||
make legal-info
|
||||
- name: Prepare Artifacts
|
||||
run: |
|
||||
cd ${{ steps.vars.outputs.out }}
|
||||
mv images ${{ steps.vars.outputs.dir }}
|
||||
ln -s ${{ steps.vars.outputs.dir }} images
|
||||
tar chfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
|
||||
mv legal-info legal-info-$target
|
||||
tar chfz legal-info-$target.tar.gz legal-info-$target
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
path: ${{ steps.vars.outputs.out }}/${{ steps.vars.outputs.tgz }}
|
||||
name: artifact-${{ matrix.variant }}-${{ matrix.platform }}
|
||||
name: artifact-${{ matrix.platform }}
|
||||
path: ${{ steps.vars.outputs.out }}/*.tar.gz
|
||||
release:
|
||||
name: Release Infix ${{ github.ref_name }}
|
||||
needs: build
|
||||
|
||||
@@ -112,25 +112,6 @@ config INFIX_ARCH
|
||||
default "riscv64" if BR2_riscv
|
||||
default "x86_64" if BR2_x86_64
|
||||
|
||||
# For /etc/os-release, VARIANT & VARIANT_ID used, e.g., in mnt script
|
||||
choice
|
||||
prompt "Select variant/flavor"
|
||||
default INFIX_VARIANT_NETCONF
|
||||
|
||||
config INFIX_VARIANT_NETCONF
|
||||
bool "NETCONF"
|
||||
help
|
||||
Managed NETCONF mode, /etc is a ramdisk, all configuration is
|
||||
generated by sysrepo plugins using NETCONF (xml) or RESTCONF.
|
||||
|
||||
config INFIX_VARIANT_CLASSIC
|
||||
bool "Classic /etc mode"
|
||||
help
|
||||
User managed mode, read-write configuration files in /etc that
|
||||
is saved across reboots.
|
||||
|
||||
endchoice
|
||||
|
||||
menu "Packages"
|
||||
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/Config.in"
|
||||
|
||||
@@ -25,6 +25,9 @@ $(config):
|
||||
%: | buildroot/Makefile
|
||||
@+$(call bmake,$@)
|
||||
|
||||
legal-info: | buildroot/Makefile
|
||||
$(call bmake,legal-info LINUX_LICENSE_FILES=COPYING)
|
||||
|
||||
# Workaround, see board/x86_64/board.mk
|
||||
test:
|
||||
@+$(call bmake,$@)
|
||||
|
||||
@@ -1,29 +1,16 @@
|
||||
[![License Badge][]][License] [![Coverity Status][]][Coverity Scan] [![Discord][discord-badge]][discord-url]
|
||||
[![License Badge][]][License] [![GitHub Status][]][GitHub] [![Coverity Status][]][Coverity Scan] [![Discord][discord-badge]][discord-url]
|
||||
|
||||
<img align="right" src="doc/logo.png" alt="Infix - Linux <3 NETCONF" width=480 border=10>
|
||||
<details><summary><b>Documentation</b></summary>
|
||||
|
||||
- **Infix In-Depth**
|
||||
- [Infix Variants](doc/variant.md)
|
||||
- [Boot Procedure](doc/boot.md)
|
||||
- [Containers in Infix](doc/container.md)
|
||||
- [Developer's Guide](doc/developers-guide.md)
|
||||
- [Discover Your Device](doc/discovery.md)
|
||||
- [Virtual Environments](doc/virtual.md)
|
||||
- [Origin & Licensing](doc/license.md)
|
||||
- **CLI Topics**
|
||||
- [Introduction to the CLI](doc/cli/introduction.md)
|
||||
- [CLI User's Guide](doc/cli/tutorial.md)
|
||||
- [Quick Overview](doc/cli/quick.md)
|
||||
|
||||
</details>
|
||||
|
||||
Infix is a free, Linux based, immutable Network Operating System (NOS)
|
||||
built on [Buildroot][1], and [sysrepo][2]. A powerful mix that ease
|
||||
porting to different platforms, simplify long-term maintenance, and
|
||||
provide made-easy management using NETCONF[^1] or the built-in [command
|
||||
line interface (CLI)][3] from a console or SSH login. *Click the
|
||||
foldout (▶ Example CLI Session) below for an example.*
|
||||
provide made-easy management using NETCONF[^1] or the built-in command
|
||||
line interface (CLI) from a console or SSH login.
|
||||
|
||||
> Click the **▶ Example CLI Session** foldout below for an example, or
|
||||
> head on over to the [Infix Documentation](doc/README.md) for more
|
||||
> information on how to set up the system.
|
||||
|
||||
Although primarily focused on switches and routers, the core values
|
||||
may be appealing for other use-cases as well:
|
||||
@@ -118,8 +105,7 @@ more information, see: [Infix in Virtual Environments](doc/virtual.md).
|
||||
>
|
||||
> For *customer specific builds* of Infix, see your product repository.
|
||||
|
||||
[^1]: NETCONF or RESTCONF, <https://datatracker.ietf.org/doc/html/rfc8040>,
|
||||
for more information, see [Infix Variants](doc/variant.md).
|
||||
[^1]: NETCONF or RESTCONF, <https://datatracker.ietf.org/doc/html/rfc8040>
|
||||
|
||||
[^2]: An immutable operating system is one with read-only file systems,
|
||||
atomic updates, rollbacks, declarative configuration, and workload
|
||||
@@ -132,6 +118,8 @@ more information, see: [Infix in Virtual Environments](doc/virtual.md).
|
||||
[3]: doc/cli/introduction.md
|
||||
[License]: https://en.wikipedia.org/wiki/GPL_license
|
||||
[License Badge]: https://img.shields.io/badge/License-GPL%20v2-blue.svg
|
||||
[GitHub]: https://github.com/kernelkit/infix/actions/workflows/build.yml/
|
||||
[GitHub Status]: https://github.com/kernelkit/infix/actions/workflows/build.yml/badge.svg
|
||||
[Coverity Scan]: https://scan.coverity.com/projects/29393
|
||||
[Coverity Status]: https://scan.coverity.com/projects/29393/badge.svg
|
||||
[discord-badge]: https://img.shields.io/discord/1182652155618918411.svg?logo=discord
|
||||
|
||||
@@ -14,6 +14,10 @@
|
||||
|
||||
#include "alder-mpp.h"
|
||||
|
||||
&ap_crit {
|
||||
temperature = <115000>;
|
||||
};
|
||||
|
||||
/ {
|
||||
model = "Alder";
|
||||
compatible = "alder,alder",
|
||||
|
||||
@@ -227,10 +227,10 @@
|
||||
|
||||
/* ETH1 (Connection to BMC) */
|
||||
|
||||
&cp0_eth1 {
|
||||
&cp0_eth2 {
|
||||
status = "okay";
|
||||
phy-mode = "sgmii";
|
||||
phys = <&cp0_comphy5 0>;
|
||||
phys = <&cp0_comphy5 2>;
|
||||
managed = "in-band-status";
|
||||
|
||||
nvmem-cells = <&base_mac 0>;
|
||||
|
||||
@@ -1,13 +0,0 @@
|
||||
#!/bin/sh
|
||||
. "$BR2_CONFIG"
|
||||
|
||||
# Prevent regen of host key at every boot, /etc is saved across reboots
|
||||
if [ -L "$TARGET_DIR/etc/dropbear" ]; then
|
||||
rm "$TARGET_DIR/etc/dropbear"
|
||||
mkdir "$TARGET_DIR/etc/dropbear"
|
||||
fi
|
||||
|
||||
# Classic builds don't have D-Bus
|
||||
if [ -f "$TARGET_DIR/etc/dnsmasq.conf" ]; then
|
||||
sed -i '/enable-dbus/d' "$TARGET_DIR/etc/dnsmasq.conf"
|
||||
fi
|
||||
@@ -1,684 +0,0 @@
|
||||
#!/bin/sh
|
||||
# COLUMS and ROWS should be set on the console, if not, use fallback
|
||||
if [ -z "$COLUMNS" ]; then
|
||||
if command -v tput; then
|
||||
COLUMNS=$(tput cols)
|
||||
else
|
||||
COLUMNS=80
|
||||
fi
|
||||
fi
|
||||
|
||||
h1()
|
||||
{
|
||||
STR="$*"
|
||||
if [ -n "$plain" ]; then
|
||||
echo "$STR" | tr '[:lower:]' '[:upper:]'
|
||||
echo "$STR" | sed 's/./=/g'
|
||||
else
|
||||
printf "\033[7m%-${COLUMNS}s\033[0m" "$STR"
|
||||
fi
|
||||
}
|
||||
|
||||
h2()
|
||||
{
|
||||
STR="$*"
|
||||
if [ -n "$plain" ]; then
|
||||
echo "$STR"
|
||||
echo "$STR" | sed 's/./-/g'
|
||||
else
|
||||
printf "\033[1m%-${COLUMNS}s\033[0m" "$STR"
|
||||
fi
|
||||
}
|
||||
|
||||
ul()
|
||||
{
|
||||
if [ -n "$plain" ]; then
|
||||
echo "__${*}__"
|
||||
else
|
||||
printf "\033[54%s\033[0m" "$*"
|
||||
fi
|
||||
}
|
||||
|
||||
em()
|
||||
{
|
||||
if [ -n "$plain" ]; then
|
||||
echo "**${*}**"
|
||||
else
|
||||
printf "\033[5m%s\033[0m" "$*"
|
||||
fi
|
||||
}
|
||||
|
||||
overview()
|
||||
{
|
||||
cat <<EOF
|
||||
$(h1 "Help System Press 'Q' to quit | Arrow keys and PgUp/PgDn to scroll")
|
||||
|
||||
$(h2 "See Also")
|
||||
help edit Tutorial on VI and Mg editors
|
||||
help net Network set up introduction
|
||||
setup User friendly setup and diagnostic tool
|
||||
|
||||
$(h2 "General Syntax")
|
||||
cmd [optional arg] E.g., use 'date -h' to get help for date command
|
||||
|
||||
$(h2 "File system")
|
||||
pwd | ls | cd Show directory, contents, or change directory
|
||||
cat file Show file contents
|
||||
vi | mg [file] Edit file with the VI or Micro Emacs editor
|
||||
|
||||
$(h2 "Services")
|
||||
initctl list Lists all configurable services (svc's)
|
||||
initctl enable svc Enable a service 'svc'
|
||||
initctl reload Reload init process' state, start/stop svc's
|
||||
initctl start svc Start a stopped service 'svc'
|
||||
initctl stop svc Stop 'svc'
|
||||
initctl restart svc Restart a running 'svc'
|
||||
initctl status [svc] Display running status of all services, or one 'svc'
|
||||
|
||||
$(h2 "Tools")
|
||||
setup User friendly setup and diagnostic tool
|
||||
date [-h] Display current time, or sets the system date
|
||||
factory Factory reset the device (on the next boot)
|
||||
hwclock [-h] Query or set the hardware clock (RTC)
|
||||
logout | Ctrl-D Log out from TTY
|
||||
mdio | mvls Low-level MDIO access, also for Marvell switch status
|
||||
tail -F file Continuously read from a file Useful for monitoring the
|
||||
health of services, see 'ls /var/log/' for log files
|
||||
less [file] Pagers provding easily scrollable content (q quits) >
|
||||
more [file] > e.g., 'cat very-long-file | less'
|
||||
most [file] > e.g., 'cat very-long-file | most'
|
||||
passwd Change user password
|
||||
pwgen Password generator
|
||||
reboot Restart the device
|
||||
reset Reset the shell prompt if it gets garbled
|
||||
|
||||
$(h2 "Network Tools")
|
||||
ethtool [-h] Ethernet stats, and low-level MAC/PHY settings
|
||||
traceroute [-h] Trace the route ip packets follow going to a host
|
||||
tcpdump [-h] Display network packet headers in real-time
|
||||
arping [-h] Ping hosts by ARP requests/replies
|
||||
fping [-h] Send ICMP ECHO_REQUEST packets to multiple hosts
|
||||
ping [-h] Send ICMP ECHO_REQUEST packets to a network host
|
||||
lynx URL [-h] The text mode web browser
|
||||
netcalc [-h] Calculate IP network settings from a IP address
|
||||
netcat [-h] NetCat - TCP/IP swiss army knife (alias: nc)
|
||||
socat [-h] Multipurpose socket relay program
|
||||
ttyd [-h] Sharing a terminal over the web
|
||||
|
||||
ifconfig [--help] See/Reconfigure available network interfaces
|
||||
route [--help] Edit the kernel's routing tables
|
||||
|
||||
ifup | ifdown IFACE Bring up/down interfaces in /etc/network/interfaces
|
||||
|
||||
ip [link|addr] Manage available network interfaces
|
||||
ip [rule|route] Manage routing tables
|
||||
bridge [link|vlan] Manage bridge ports and VLANs
|
||||
|
||||
scp Securely copy a file to a remote host file system
|
||||
tftp Copy a file to/from a remote host
|
||||
ftpput Store a local file on a remote machine via FTP
|
||||
ftpget Retrieve a remote file via FTP
|
||||
wget Get a file using HTTP or FTP from a remote host
|
||||
|
||||
$(h2 "Overview Commands")
|
||||
df -h List disk usage (in human readable format)
|
||||
free List memory usage
|
||||
ps List running processes
|
||||
show [arg] Show system status, see 'show help' for more info
|
||||
top Displays CPU usage and top list of running tasks
|
||||
|
||||
$(h2 "Interesting Files")
|
||||
/etc/default/svc Command line args for service 'svc' (see above)
|
||||
/etc/rc.local Local setup, runs after all services have started
|
||||
/etc/network/ Directory of networking setup, see 'help net'
|
||||
|
||||
$(h2 "Example Commands")
|
||||
cd /tmp; wget ftp://192.168.55.43/file && cat file
|
||||
cd /var/log; tftp -p -l messages 192.168.55.43
|
||||
cat /proc/net/arp
|
||||
edit /etc/network/interfaces
|
||||
|
||||
$(h2 "See Also")
|
||||
help edit Tutorial on VI and Mg editors
|
||||
help net Network set up introduction
|
||||
setup User friendly setup and diagnostic tool
|
||||
EOF
|
||||
}
|
||||
|
||||
vi()
|
||||
{
|
||||
cat <<EOF
|
||||
$(h1 "Visual Editor (vi)")
|
||||
Vi is the de facto standard editor in UNIX systems. It comes with two modes:
|
||||
|
||||
- $(em "Command mode (default):") administrative tasks such as saving files,
|
||||
executing commands, moving the cursor, cutting and pasting lines or words,
|
||||
as well as finding and replacing. $(em "Return to command mode with Esc")
|
||||
|
||||
- $(em "Insert mode:") Everything that's typed in this mode is interpreted as
|
||||
input and placed in the file.
|
||||
|
||||
$(h2 "Navigation commands")
|
||||
|
||||
h - move the cursor one character to the left
|
||||
j - move the cursor down one character
|
||||
k - mode the cursor up one character
|
||||
l - move the cursor right one character
|
||||
b - move to beginning of word, or previous word
|
||||
w - move to next word
|
||||
0 - move to beginning of line
|
||||
$ - move to end of line
|
||||
:0 - move to beginning of file
|
||||
G - move to end of file
|
||||
|
||||
$(h2 "Editing commands")
|
||||
|
||||
u - undo last operation
|
||||
x - delete the character the cursor is on
|
||||
cw - change word, from position of cursor
|
||||
dw - delete to end of word
|
||||
dd - delete the line the character is on
|
||||
p - paste (line, word, or char) after cursor
|
||||
P - paste (line, word, or char) before cursor
|
||||
|
||||
$(h2 "Saving and quit commands")
|
||||
|
||||
:w - save the current file
|
||||
:w filename - save a copy of the file named filename
|
||||
:w! - try to save the file, even if it is read only
|
||||
:wq - save and quit vi
|
||||
ZZ - save and quit vi
|
||||
:wq! - try to save the file if it is read only, quit if successful
|
||||
:wq filename - save a copy of the file named filename and quit
|
||||
:wq! filename - save a copy of the file named filename and quit,
|
||||
override read only permissions if possible
|
||||
:q - quit vi
|
||||
:q! - quit vi even if the file has unsaved changes
|
||||
|
||||
$(h2 "Enter insert mode")
|
||||
|
||||
a - append new text after the cursor
|
||||
i - insert text before the cursor
|
||||
o - open a new line below the cursor
|
||||
O - open a new line above the cursor
|
||||
|
||||
> Return to command mode with Esc
|
||||
|
||||
EOF
|
||||
}
|
||||
|
||||
emacs()
|
||||
{
|
||||
cat <<EOF
|
||||
$(h1 "Micro Emacs (mg)")
|
||||
Mg is a bit more user-friendly than vi. It has the same familiar interface
|
||||
as Notepad, but with slightly different keybindings.
|
||||
|
||||
$(h2 "Introduction")
|
||||
|
||||
Most commands involve using the Control ("Ctrl") or the Meta ("Alt") key.
|
||||
The following conventions are used in the online help:
|
||||
|
||||
C-<chr> means hold down the Control key while typing the character <chr>
|
||||
M-<chr> means hold down the Alt key while typing the character <chr>
|
||||
|
||||
If you don't have a Meta/Alt key, you can use Esc instead. Press and release
|
||||
the Esc key and then type <chr>. This is equivalent to M-<chr>.
|
||||
|
||||
$(h2 "Navigation")
|
||||
|
||||
Though arrow keys, Home/End, and PgUp/PgDn usually work, using Mg over serial
|
||||
console can sometimes cause these keys to be mismapped by terminal program.
|
||||
|
||||
C-f Move forward one character (can also use right arrow key)
|
||||
C-b Move backward one character (can also use left arrow key)
|
||||
C-p Move up one line (can also use up arrow key)
|
||||
C-n Move down one line (can also use down arrow key)
|
||||
M-f Move forward one word
|
||||
M-b Move backward one word
|
||||
C-a Move to beginning of line (can also use Home key)
|
||||
C-e Move to end of line (can also use End key)
|
||||
C-v Move forward one page (can also use PgDn/Page Down key)
|
||||
M-v Move backward one page (can also use PgUp/Page Up key)
|
||||
M-< Move to beginning of file
|
||||
M-> Move to end of file
|
||||
C-x g Move to line number
|
||||
|
||||
$(h2 "Editing")
|
||||
|
||||
All edit commands that kill (cut) text is placed in a kill ring (clipboard).
|
||||
Note: when marking text, there is no visual mark.
|
||||
|
||||
C-_ Undo, also C-x u
|
||||
M-% Replace word/string in file, from cursor position
|
||||
M-q Reformat paragraph (set fill column with C-x f)
|
||||
C-s Search forward (type C-s again to find next)
|
||||
C-r Reversed search
|
||||
C-Space Set beginning of mark (beginning of selected text)
|
||||
C-x C-x Jump back and forth between mark and cursor position
|
||||
C-x h Mark whole buffer
|
||||
C-w Wipe (cut) region from mark to cursor position
|
||||
M-w Copy region from mark to cursor position
|
||||
C-y Yank (paste) text from kill ring
|
||||
C-k Kill (cut) to end of line
|
||||
M-Backspace Kill (delete) previous word
|
||||
M-d Kill (delete) next word
|
||||
C-d Delete character to the right
|
||||
C-o Open new line at cursor
|
||||
|
||||
$(h2 "General Commands")
|
||||
|
||||
C-g Abort current command
|
||||
C-l Recenter buffer on current line
|
||||
C-h b List all keybindings
|
||||
M-! Run shell command, output in new buffer
|
||||
C-z Suspend Mg, return to shell, use 'fg' to get back
|
||||
C-x C-f Open file
|
||||
C-x C-i Insert file at cursor position
|
||||
C-x C-s Save file
|
||||
C-x s Save file (interactive)
|
||||
C-x k Kill (close) file
|
||||
C-x C-b List open buffers (files)
|
||||
C-x b Switch to another buffer
|
||||
C-x C-c Exit
|
||||
|
||||
$(h2 "Window Commands")
|
||||
|
||||
C-x 0 Unsplit, keep other window
|
||||
C-x 1 Unsplit, keep this window
|
||||
C-x 2 Split window in two
|
||||
C-x o Go to other window
|
||||
C-x p Go to previous window
|
||||
C-x n Go to next window
|
||||
C-x ^ Enlarge this split
|
||||
|
||||
EOF
|
||||
}
|
||||
|
||||
editor()
|
||||
{
|
||||
case $1 in
|
||||
vi)
|
||||
vi
|
||||
;;
|
||||
ed* | em* | mg)
|
||||
emacs
|
||||
;;
|
||||
*)
|
||||
vi
|
||||
emacs
|
||||
cat <<EOF
|
||||
$(h1 "Summary")
|
||||
Use Mg or GNU Nano if you are a beginner. The system is set up to so you can
|
||||
use the 'edit' command, which will start GNU Nano:
|
||||
|
||||
edit /etc/rc.local # Starts GNU Nano
|
||||
|
||||
EOF
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
networking()
|
||||
{
|
||||
cat <<EOF
|
||||
$(h1 "Networking")
|
||||
This section details how to set up everything from basic to advanced networking.
|
||||
Topics covered include:
|
||||
|
||||
- Static vs Dynamic Addresses
|
||||
- VLAN Interfaces
|
||||
- Bridging Interfaces
|
||||
- Link Aggregation (bonding)
|
||||
- Persistent Configuration
|
||||
|
||||
Please note, the terms 'port' and 'interface' may be used interchangably in
|
||||
the following text (and elsewher online as well). Usually the term 'port' is
|
||||
reserved for Ethernet links attached to a switch or bridge, while the term
|
||||
'interface' more generically refers to the physical interface in a system.
|
||||
|
||||
|
||||
$(h2 "Static vs Dynamic Addresses")
|
||||
|
||||
An IPv4 address consists of four "octets" separated by periods. A static IPv4
|
||||
address can look like this:
|
||||
|
||||
192.168.1.42
|
||||
|
||||
However, for networking to function properly, a device usually needs a netmask,
|
||||
default route, NTP server, and at least one DNS address. Setting all these up
|
||||
statically is a lot of work to maintain, in particular with many devices.
|
||||
|
||||
For both IPv4 and IPv6 there is an alternative called DHCP. It is a dynamic
|
||||
protocol where a server on request from a client device hands out a "lease" of
|
||||
an IP address, as well as lot of other network parameters, including but not
|
||||
limited to the ones already mentioned. A client device can give hints to the
|
||||
server, e.g., its hostname, MAC address (default), or other client identifier.
|
||||
It is up to the server to honor these hints or not, but it is very common to
|
||||
set up the server to honor the client's hostname and automatically update the
|
||||
central name server (DNS) when the client is online.
|
||||
|
||||
| There are many other interesting aspects to DHCP not covered here.
|
||||
| For instance, DHCP relay servers (proxies), that can be used to
|
||||
| forward DHCP requests from very large networks to a central server.
|
||||
| Some relay "agents" even support something called Option 82, which
|
||||
| when running on a simple switch, can attach port and relay info to
|
||||
| the client's DHCP request -- allowing the server to assign an IP
|
||||
| address per port, even on remote switches (with a relay agent).
|
||||
|
||||
When your interface is setup with DHCP, use the 'ifconfig' or 'ip addr' tools
|
||||
to see which address you got, if needed (see next section).
|
||||
|
||||
In cases when the DHCP client cannot find a DHCP server, and thus not obtain a
|
||||
lesae, the system falls back to set a link-local address (169.254.*.*). This
|
||||
can be disabled by editing the file /etc/dhcpcd.conf, adding:
|
||||
|
||||
noipv4ll
|
||||
|
||||
A link-local address is however very useful, in particular in combination with
|
||||
mDNS to discover and access a device you do not know, or do not want to know,
|
||||
the IP address to. See more in the next section.
|
||||
|
||||
|
||||
$(h2 "DNS and mDNS")
|
||||
|
||||
Managing a central DNS is both painful and time consuming, most networks, and
|
||||
in particular industrial, therefore only set up a DNS for static servers and
|
||||
resources. Leaving end devices, switches, and in many cases even routers,
|
||||
without a human-friendly name on the network. This have misled many to think
|
||||
that they need to know the IP address, and often opt for static addresses on
|
||||
equipment. Meaning many devices out-of-the-box have a static address set that
|
||||
need to be manually changed before the device is deployed on the network.
|
||||
|
||||
A less time consuming, and human-friendly, way is to enable mDNS (multicast
|
||||
DNS). With this protocol the device notifies all neighbors on the same LAN
|
||||
of how to reach it:
|
||||
|
||||
"Hello everyone, my address is 169.254.47.11, you can call me device.local"
|
||||
|
||||
Any other device that also has mDNS enabled can then automaticall update a
|
||||
local database of name-to-address mappings. Usually the name sent out is
|
||||
the device's hostname. (It is up to the device manufacturer to set a useful
|
||||
default hostname, i.e., model-01-02-03, where the suffix is the last octets
|
||||
of the base MAC address, from the product label on the case.)
|
||||
|
||||
As you can see, in combination with a link-local address (previous section)
|
||||
mDNS is a very attractive combination that greatly simplify device management.
|
||||
|
||||
Tools:
|
||||
|
||||
avahi-browse -a
|
||||
ping foo.local
|
||||
|
||||
mDNS, or more correctly mDNS-SD, is also used for *Service Discovery*. E.g.,
|
||||
a printer can publish IPP records with meta data on the printer type and model
|
||||
or donwload URL for drivers. Switches and routers usually publish how they
|
||||
can be reached: HTTP/HTTPS and SSH.
|
||||
|
||||
mDNS is supported in this product and should be enabled by default. To
|
||||
verify that it works, in Windows, macOS, or Linux, open your web browser
|
||||
and point it to <https://hostname-01-02-03.local>. This is the hostname
|
||||
and three last octets of the device's base MAC address. You can also use
|
||||
mDNS browsers or command line tools like mdns-scan
|
||||
|
||||
|
||||
$(h2 "VLAN Interfaces")
|
||||
|
||||
A VLAN interface in Linux is an "upper" interface, e.g., 'eth0.1'. It is
|
||||
where you set an IP address and interact with th rest of the world. The
|
||||
base/raw/lower interface, here 'eth0', is the physical interface on which
|
||||
Ethernet packets ingress and egress with a VLAN tag. To create 'eth0.1':
|
||||
|
||||
ip link add eth0.1 link eth0 vlan id 1
|
||||
|
||||
In Linux a VLAN interface is a "stackable" entity. Many VLAN interfaces
|
||||
can be built on top of each other. When injecting a packet on the top
|
||||
most interface, the kernel adds the corresponding VLAN "tag" when the
|
||||
packet goes down the order of stacked interfaces, and then finally hits
|
||||
the physical interface and proceeds to egress onto the media.
|
||||
|
||||
ip link add eth0.1.2 link eth0.1 vlan id 2
|
||||
|
||||
Injecting a packet on 'eth0.1.2' creates a double-tagged VLAN frame when
|
||||
the packet egresses 'eth0'. The outermost tag has VID 1 and the inner
|
||||
VID is 2.
|
||||
|
||||
VLAN interfaces can be used for many things, here we will focus on their
|
||||
use as upper interface on a bridge.
|
||||
|
||||
|
||||
$(h2 "Bridging Interfaces")
|
||||
|
||||
A bridge is the correct name for a switch. In the context of this text,
|
||||
however, we will use the term to refer to the Linux bridge module in the
|
||||
kernel, which implements an advanced software switch. The Linux bridge
|
||||
supports "offloading" many switching functions to an underlying switching
|
||||
chipset, when available. This greatly simplifies managing that switch since
|
||||
the same tools one use to manage the bridge will, by extension, also be used
|
||||
to manage the switch.
|
||||
|
||||
To create a bridge in Linux:
|
||||
|
||||
ip link add br0 type bridge
|
||||
|
||||
To add three ports (interfaces) to the bridge we use:
|
||||
|
||||
ip link set eth0 master br0
|
||||
ip link set eth1 master br0
|
||||
ip link set eth2 master br0
|
||||
|
||||
Bring all ports and the bridge 'up' and you have a working switch! Any frame
|
||||
injected on eth0 (from the outside) can be switched to either of eth1, eth2,
|
||||
*or* br0. As soon as the bridge has learned where end devices are connected,
|
||||
none of the other ports will see the traffic -- like a regular switch.
|
||||
|
||||
Note: these ports should not (cannot) have any IP address. Instead, any IP
|
||||
address is set on 'br0'. To disable IPv6 link-local address, set the
|
||||
/proc/sys/net/ipv6/conf/eth0/disable_ipv6 sysctl file to '1'.
|
||||
|
||||
|
||||
$(h2 "Bridging and VLANs")
|
||||
|
||||
A VLAN-aware bridge works the same way, only with VLAN separation taken into
|
||||
account. All communication, as well as MAC address learning, is limited to
|
||||
ports in the same VLAN. The syntax is slightly different and requires a few
|
||||
more steps:
|
||||
|
||||
ip link add br0 type bridge vlan_filtering 1
|
||||
ip link set eth0 master br0
|
||||
ip link set eth1 master br0
|
||||
ip link set eth2 master br0
|
||||
ip link set eth3 master br0
|
||||
|
||||
To assign ports to different VLANs, and make sure they are regular "access"
|
||||
ports (untagged). We assign eth0 and eth1 to VLAN 1 and the others to VLAN 2:
|
||||
|
||||
bridge vlan add vid 1 dev eth0 pvid untagged
|
||||
bridge vlan add vid 1 dev eth1 pvid untagged
|
||||
bridge vlan add vid 2 dev eth2 pvid untagged
|
||||
bridge vlan add vid 2 dev eth3 pvid untagged
|
||||
|
||||
Here's the twist, to be able to reach the bridge (switch) itself from each
|
||||
VLAN, we need to ensure the bridge itself is a tagged member of each VLAN:
|
||||
|
||||
bridge vlan add vid 1 dev br0 self
|
||||
bridge vlan add vid 2 dev br0 self
|
||||
|
||||
This way we can add VLAN interfaces on top of br0, which we in turn can set
|
||||
a static or dynamic IP address on:
|
||||
|
||||
ip link add vlan1 link br0 type vlan id 1
|
||||
ip link add vlan2 link br0 type vlan id 2
|
||||
|
||||
The resulting stack of interfaces look like this:
|
||||
|
||||
:
|
||||
vlan1 : vlan2 Layer-3 :: IP Networking
|
||||
\\ : / _________________________
|
||||
.-------------.
|
||||
| br0 | Layer-2 :: Switching
|
||||
'-------------' _________________________
|
||||
/ | : | \\
|
||||
eth0 eth1 : eth2 eth3 Layer-1 :: Link layer
|
||||
:
|
||||
|
||||
|
||||
$(h2 "Persistent Configuration")
|
||||
|
||||
A simple end device can get by with the following in /etc/network/interfaces:
|
||||
|
||||
auto lo
|
||||
iface lo inet loopback
|
||||
|
||||
auto eth0
|
||||
iface eth0 inet dhcp
|
||||
|
||||
This brings up both the loopback (required for UNIX networking to function),
|
||||
and the (presumed only) Ethernet interface. The loopback gets its standard
|
||||
address, 127.0.0.1, and eth0 will request its IP address using DHCP.
|
||||
|
||||
To set up the bridge example (above), is actually quite a lot easier than
|
||||
using the command line ip and bridge tools. Create the file 'bridge':
|
||||
|
||||
edit /etc/network/interfaces.d/bridge
|
||||
|
||||
Paste in the following content:
|
||||
|
||||
iface e0
|
||||
bridge-access 1
|
||||
iface e1
|
||||
bridge-access 1
|
||||
iface e2
|
||||
bridge-access 2
|
||||
iface e3
|
||||
bridge-access 2
|
||||
|
||||
auto br0
|
||||
iface br0
|
||||
bridge-ports e0 e1 e2 e3
|
||||
bridge-vlan-aware yes
|
||||
bridge-stp on
|
||||
bridge-vids 1 2
|
||||
|
||||
auto vlan1
|
||||
iface vlan1 inet dhcp
|
||||
vlan-id 1
|
||||
vlan-raw-device br0
|
||||
|
||||
auto vlan2
|
||||
iface vlan2 inet static
|
||||
vlan-id 2
|
||||
vlan-raw-device br0
|
||||
address 192.168.2.1/24
|
||||
|
||||
Notice how 'vlan1' only has a DHCP and 'vlan2' uses a static address. It is
|
||||
possible to combine the two if needed. Use 'inet dhcp' and add an 'address'
|
||||
statement to the iface stanza.
|
||||
|
||||
|
||||
$(h2 "Port Classification")
|
||||
|
||||
The bundled 'show' script is a very handy tool. It use several tricks to make
|
||||
information about the system more accessible. On switching capable hardware
|
||||
products, switch ports are identified early at system bootstrap and placed in
|
||||
the 'port' group. See 'ip link' output:
|
||||
|
||||
...
|
||||
4: e0: <BROADCAST,MULTICAST> master br0 state UP $(em "group port")
|
||||
link/ether 52:54:00:12:34:56 brd ff:ff:ff:ff:ff:ff
|
||||
...
|
||||
|
||||
When running in Qemu or other hardware it may be useful to manually classify
|
||||
certain interfaces as ports. This can be achieved in many ways, here we show
|
||||
two. First /etc/mactab, which is read at boot to rename interfaces according
|
||||
their matching MAC address, one interface per line:
|
||||
|
||||
e0 52:54:00:12:34:56
|
||||
e1 52:54:00:12:34:57
|
||||
e2 52:54:00:12:34:58
|
||||
e3 52:54:00:12:34:59
|
||||
|
||||
Another way is to add something like this to /etc/rc.local:
|
||||
|
||||
for port in eth0 eth1 eth3 eth4; do
|
||||
ip link set \$port group port
|
||||
done
|
||||
|
||||
|
||||
$(h2 "Interesting Files")
|
||||
|
||||
- /etc/dhcpcd.conf General DHCP and ZeroConf (LL) settings
|
||||
- /etc/network/interfaces The original, useful for small setups
|
||||
- /etc/network/interfaces.d/* Snippets, useful for non-trivial setups
|
||||
- /etc/mactab Rename interfaces: 'NAME16CHARS WHITESPACE MAC'
|
||||
- /etc/sysctl.conf Interface and TCP/IP settings, e.g., routing
|
||||
- /etc/sysctl.d/* Snippets, useful for per-subsystem settings
|
||||
|
||||
|
||||
$(h1 "Summary")
|
||||
All persistent networking is set up in /etc/network/interfaces using the
|
||||
program ifupdown-ng. The tools to reconfigure networking at runtime are:
|
||||
|
||||
ifup [-a] [IFACES]
|
||||
ifdown [-a] [IFACES]
|
||||
|
||||
When changing the configuration at runtime you usually have to bring the
|
||||
affected interfaces down (ifdown e0 e1 e2 e3), if they were set up with
|
||||
/etc/network/interfaces before. Then do the change, and bring it all up
|
||||
again.
|
||||
|
||||
Both tools understand dependencies between interfaces, so when a 'ifup -a'
|
||||
command is received it brings up all interfaces: adding links to br0 before
|
||||
adding VLANs, the vlan1 and vlan2 interfaces on top so it of it all. Then
|
||||
finally it can start the DHCP client on vlan1 and set the static IP address
|
||||
on vlan2.
|
||||
|
||||
$(em ">>> Be careful with these tools when logged in remotely! <<<")
|
||||
|
||||
EOF
|
||||
}
|
||||
|
||||
topic()
|
||||
{
|
||||
topic=$1
|
||||
[ -n "$1" ] && shift
|
||||
|
||||
case $topic in
|
||||
ed*)
|
||||
# shellcheck disable=SC2068
|
||||
editor $*
|
||||
;;
|
||||
net*)
|
||||
networking
|
||||
;;
|
||||
*)
|
||||
overview
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
if [ "$1" = "-p" ]; then
|
||||
shift
|
||||
pager="cat"
|
||||
plain="yes"
|
||||
else
|
||||
if command -v most; then
|
||||
pager=most
|
||||
elif command -v less; then
|
||||
pager="less -R"
|
||||
elif command -v more; then
|
||||
pager="more"
|
||||
else
|
||||
pager="cat"
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ -t 1 ] ; then
|
||||
fn=$(mktemp /tmp/system-help.XXXXXX)
|
||||
# shellcheck disable=SC2086,SC2068
|
||||
topic $@ >"$fn"
|
||||
$pager "$fn"
|
||||
rm "$fn"
|
||||
else
|
||||
topic "$*"
|
||||
fi
|
||||
@@ -1,16 +0,0 @@
|
||||
#!/bin/sh
|
||||
# Changes hostname in /etc/hostname and /etc/hosts
|
||||
|
||||
current=$(cat /etc/hostname)
|
||||
newname=$1
|
||||
|
||||
[ -n "$newname" ] || exit 1
|
||||
|
||||
sed -i "s/$current/$newname/" /etc/hosts
|
||||
sed -i "s/$current/$newname/" /etc/hostname
|
||||
|
||||
hostname $newname
|
||||
|
||||
initctl touch sysklogd
|
||||
initctl touch dnsmasq
|
||||
initctl reload
|
||||
@@ -1,3 +0,0 @@
|
||||
#!/bin/sh
|
||||
pdmenu
|
||||
clear
|
||||
@@ -1,327 +0,0 @@
|
||||
#!/bin/sh
|
||||
# Displays basic information about the system
|
||||
# shellcheck disable=SC2048,SC2086
|
||||
. /etc/os-release
|
||||
|
||||
bopt="-c"
|
||||
opt="-br"
|
||||
all=""
|
||||
plain=""
|
||||
|
||||
TTY=$(resize)
|
||||
eval "$TTY"
|
||||
|
||||
# COLUMS and ROWS should be set on the console, if not, use fallback
|
||||
if [ -z "$COLUMNS" ]; then
|
||||
if command -v tput; then
|
||||
COLUMNS=$(tput cols)
|
||||
else
|
||||
COLUMNS=80
|
||||
fi
|
||||
fi
|
||||
|
||||
h1()
|
||||
{
|
||||
STR="$*"
|
||||
if [ -n "$plain" ]; then
|
||||
echo "$STR" | tr '[:lower:]' '[:upper:]'
|
||||
else
|
||||
printf "\033[7m%-${COLUMNS}s\033[0m\n" "$STR"
|
||||
fi
|
||||
}
|
||||
|
||||
h2()
|
||||
{
|
||||
STR="$*"
|
||||
if [ -n "$plain" ]; then
|
||||
echo "$STR"
|
||||
echo "$STR" | sed 's/./-/g'
|
||||
else
|
||||
printf "\033[1m%-${COLUMNS}s\033[0m\n" "$STR"
|
||||
fi
|
||||
}
|
||||
|
||||
dm()
|
||||
{
|
||||
if [ -n "$plain" ]; then
|
||||
echo "${*}"
|
||||
else
|
||||
printf "\033[2m%s\033[0m\n" "$*"
|
||||
fi
|
||||
}
|
||||
|
||||
ul()
|
||||
{
|
||||
if [ -n "$plain" ]; then
|
||||
printf "__%s__" "$*"
|
||||
else
|
||||
printf "\033[4%s\033[0m" "$*"
|
||||
fi
|
||||
}
|
||||
|
||||
em()
|
||||
{
|
||||
if [ -n "$plain" ]; then
|
||||
printf "**%s**" "$*"
|
||||
else
|
||||
printf "\033[5m%s\033[0m" "$*"
|
||||
fi
|
||||
}
|
||||
|
||||
usage()
|
||||
{
|
||||
cat <<EOF
|
||||
usage:
|
||||
show [opt] cmd
|
||||
|
||||
options:
|
||||
-a Show all, of something
|
||||
-f Show full output, not brief port/iface listings
|
||||
-h Show this help text
|
||||
-n Show output without any footer
|
||||
-p Show plain output, no bells or whistles
|
||||
|
||||
commands:
|
||||
port PORT Show port configuration and link information
|
||||
ports Show ports available for bridging
|
||||
vlans Show port groups in bridge
|
||||
ifaces Show interfaces and their addresses
|
||||
fdb Show forwarding database (unicast)
|
||||
mdb Show multicast forwarding database
|
||||
ip route Show routing table
|
||||
log [FILE] Show latest entries from syslog, or other FILE
|
||||
rmon PORT Show RMON counters for PORT (when applicable)
|
||||
system Show OS details
|
||||
version Show OS verson
|
||||
EOF
|
||||
}
|
||||
|
||||
# Usage 1: show port eth0
|
||||
# Usage 2: show port
|
||||
# Usage 3: show ports
|
||||
#
|
||||
# The first show ethtool output for 'eth0' (in this case). The latter
|
||||
# two are the same, showing a summary of all interfaces classified as
|
||||
# access ports.
|
||||
ports()
|
||||
{
|
||||
if [ $# -gt 0 ] && [ -e "/sys/class/net/$1" ]; then
|
||||
for port in $*; do
|
||||
ethtool "$port"
|
||||
done
|
||||
return
|
||||
fi
|
||||
|
||||
h1 "PORT STATE MAC ADDRESS FLAGS"
|
||||
if grep -q port /etc/iproute2/group && [ -z "$all" ]; then
|
||||
ip $opt link show group port
|
||||
else
|
||||
ip $opt link show
|
||||
fi
|
||||
|
||||
if [ -z "$plain" ] && [ -z "$nofoot" ]; then
|
||||
dm "______________________________________________________________________________"
|
||||
dm "Use: '[ip|bridge] --help' and '[ip|bridge] link help' for more details."
|
||||
fi
|
||||
}
|
||||
|
||||
vlans()
|
||||
{
|
||||
h1 "INTERFACE VLAN FLAGS"
|
||||
bridge $bopt vlan show |tail +2 | awk 'NF { iface=$1; vid=$2; printf("%-16s %4d ", iface, vid); for (i=3; i <= NF; i++) printf("%s ", $i); printf("\n"); }'
|
||||
if [ -z "$plain" ] && [ -z "$nofoot" ]; then
|
||||
dm "______________________________________________________________________________"
|
||||
dm "See: 'bridge --help' and 'bridge vlan help' for more details."
|
||||
fi
|
||||
}
|
||||
|
||||
ifaces()
|
||||
{
|
||||
h1 "INTERFACE STATE ADDRESS"
|
||||
if [ -n "$all" ]; then
|
||||
ip $opt addr show
|
||||
elif grep -q iface /etc/iproute2/group; then
|
||||
ip $opt addr show group iface
|
||||
else
|
||||
ip $opt addr show |awk '{ if ($1 !~ /eth[0-9]*/ && $1 !~ /.*@NONE/) { print }}'
|
||||
fi
|
||||
if [ -z "$plain" ] && [ -z "$nofoot" ]; then
|
||||
dm "______________________________________________________________________________"
|
||||
dm "See: 'ip --help' and 'ip address help' for more details."
|
||||
fi
|
||||
}
|
||||
|
||||
log()
|
||||
{
|
||||
if [ -n "$1" ] && [ -r "/var/log/$1" ]; then
|
||||
fn="/var/log/$1"
|
||||
else
|
||||
fn="/var/log/syslog"
|
||||
fi
|
||||
if [ -n "$all" ]; then
|
||||
cat $fn
|
||||
else
|
||||
tail -$LINES $fn
|
||||
fi
|
||||
if [ -z "$plain" ] && [ -z "$nofoot" ]; then
|
||||
dm "______________________________________________________________________________"
|
||||
dm "See: 'tail -25 /log/FILE', 'tail -F /log/FILE' to continuously monitor files."
|
||||
fi
|
||||
}
|
||||
|
||||
rmon()
|
||||
{
|
||||
if [ -z "$*" ]; then
|
||||
echo "Missing argument, see 'show port' for available interfaces"
|
||||
exit 1
|
||||
fi
|
||||
for port in $*; do
|
||||
ethtool -S "$port"
|
||||
done
|
||||
if [ -z "$plain" ] && [ -z "$nofoot" ]; then
|
||||
dm "______________________________________________________________________________"
|
||||
dm "See: 'ethtool --help' for more details."
|
||||
fi
|
||||
}
|
||||
|
||||
rstp()
|
||||
{
|
||||
mstpctl showbridge
|
||||
echo "br0 port info"
|
||||
mstpctl showport br0
|
||||
}
|
||||
|
||||
fdb()
|
||||
{
|
||||
bridge $bopt fdb show
|
||||
}
|
||||
|
||||
mdb()
|
||||
{
|
||||
bridge $bopt mdb show
|
||||
}
|
||||
|
||||
routes()
|
||||
{
|
||||
ip $opt route show
|
||||
}
|
||||
|
||||
igmp()
|
||||
{
|
||||
querierctl $@
|
||||
}
|
||||
|
||||
system()
|
||||
{
|
||||
h1 "SYSTEM INFORMATION"
|
||||
echo "System Name : $(uname -n)"
|
||||
echo "System Variant : $VARIANT"
|
||||
echo "System Description : $PRETTY_NAME"
|
||||
echo "System Contact : $HOME_URL"
|
||||
echo "System Timezone : $(cat /etc/timezone)"
|
||||
echo "System Type : $NAME"
|
||||
echo "System Version : $(cat /etc/version)"
|
||||
echo "System Arch : $(uname -m)"
|
||||
echo "Kernel Version : $(uname -sr)"
|
||||
}
|
||||
|
||||
version()
|
||||
{
|
||||
cat /etc/version
|
||||
}
|
||||
|
||||
while [ "$1" != "" ]; do
|
||||
case $1 in
|
||||
-a)
|
||||
all=1
|
||||
;;
|
||||
-f)
|
||||
opt=""
|
||||
if [ -n "$plain" ]; then
|
||||
opt="-color=never"
|
||||
bopt="-color=never"
|
||||
fi
|
||||
;;
|
||||
-n)
|
||||
nofoot="yes"
|
||||
;;
|
||||
-p)
|
||||
plain="yes"
|
||||
opt="$opt -color=never"
|
||||
bopt="$bopt -color=never"
|
||||
;;
|
||||
-h)
|
||||
usage
|
||||
exit 0
|
||||
;;
|
||||
*)
|
||||
break
|
||||
esac
|
||||
shift
|
||||
done
|
||||
|
||||
cmd=$1
|
||||
if [ -n "$cmd" ]; then
|
||||
shift
|
||||
fi
|
||||
|
||||
case $cmd in
|
||||
help)
|
||||
usage
|
||||
;;
|
||||
port*)
|
||||
ports $*
|
||||
;;
|
||||
vlan*)
|
||||
vlans
|
||||
;;
|
||||
fdb)
|
||||
fdb
|
||||
;;
|
||||
mdb)
|
||||
mdb
|
||||
;;
|
||||
if*)
|
||||
ifaces
|
||||
;;
|
||||
ip)
|
||||
cmd=$1
|
||||
shift
|
||||
case $cmd in
|
||||
addr*)
|
||||
ifaces
|
||||
;;
|
||||
route*)
|
||||
routes
|
||||
;;
|
||||
igmp*)
|
||||
igmp $*
|
||||
;;
|
||||
*)
|
||||
usage
|
||||
;;
|
||||
esac
|
||||
;;
|
||||
log)
|
||||
log $1
|
||||
;;
|
||||
rmon)
|
||||
rmon $*
|
||||
;;
|
||||
route*)
|
||||
routes
|
||||
;;
|
||||
span*)
|
||||
rstp
|
||||
;;
|
||||
sys*)
|
||||
system
|
||||
;;
|
||||
ver*)
|
||||
version
|
||||
;;
|
||||
*)
|
||||
usage
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
@@ -1,55 +0,0 @@
|
||||
#!/bin/sh
|
||||
#set -x
|
||||
|
||||
usage()
|
||||
{
|
||||
cat <<EOF
|
||||
usage:
|
||||
yorn [-h] ["Do you want to run command?" command]
|
||||
|
||||
options:
|
||||
-h Show this help text
|
||||
-p Show plain output, no bells or whistles
|
||||
|
||||
Displays the yes-or-no question and runs command on yes.
|
||||
EOF
|
||||
}
|
||||
|
||||
if [ -z "$1" ]; then
|
||||
usage
|
||||
exit 1
|
||||
fi
|
||||
|
||||
case $1 in
|
||||
-h)
|
||||
usage
|
||||
exit 0
|
||||
;;
|
||||
-p)
|
||||
plain=1
|
||||
shift
|
||||
;;
|
||||
*)
|
||||
;;
|
||||
esac
|
||||
|
||||
question=$1
|
||||
shift
|
||||
command=$*
|
||||
if [ -z "$command" ]; then
|
||||
usage
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ -z "$plain" ]; then
|
||||
if dialog --erase-on-exit --colors --defaultno --yesno "\Zb$question\ZB" 0 0; then
|
||||
yorn=y
|
||||
fi
|
||||
else
|
||||
# shellcheck disable=SC2162,SC3045
|
||||
read -n 1 -p "$question (y/N): " yorn
|
||||
fi
|
||||
|
||||
if [ "$yorn" = "y" ] || [ "$yorn" = "Y" ]; then
|
||||
$command
|
||||
fi
|
||||
@@ -1,18 +0,0 @@
|
||||
# System-wide .bashrc file for interactive bash(1) shells.
|
||||
|
||||
# If not running interactively, don't do anything
|
||||
[ -z "$PS1" ] && return
|
||||
|
||||
# Reevaluate for each line, in case hostname changes
|
||||
function prompt_command
|
||||
{
|
||||
PS1="\u@$(hostname):\w\$ "
|
||||
}
|
||||
export PROMPT_COMMAND=prompt_command
|
||||
|
||||
# check the window size after each command and, if necessary,
|
||||
# update the values of LINES and COLUMNS.
|
||||
shopt -s checkwinsize
|
||||
|
||||
# Disble built-ins
|
||||
enable -n help
|
||||
@@ -1,51 +0,0 @@
|
||||
# Infix's configuration for dhcpcd.
|
||||
# See dhcpcd.conf(5) for details.
|
||||
|
||||
# Allow users of this group to interact with dhcpcd via the control socket.
|
||||
#controlgroup wheel
|
||||
|
||||
# Inform the DHCP server of our hostname for DDNS.
|
||||
#hostname
|
||||
|
||||
# Use the hardware address of the interface for the Client ID.
|
||||
#clientid
|
||||
# or
|
||||
# Use the same DUID + IAID as set in DHCPv6 for DHCPv4 ClientID as per RFC4361.
|
||||
# Some non-RFC compliant DHCP servers do not reply with this set.
|
||||
# In this case, comment out duid and enable clientid above.
|
||||
duid
|
||||
|
||||
# Persist interface configuration when dhcpcd exits.
|
||||
persistent
|
||||
|
||||
# vendorclassid is set to blank to avoid sending the default of
|
||||
# dhcpcd-<version>:<os>:<machine>:<platform>
|
||||
vendorclassid
|
||||
|
||||
# A list of options to request from the DHCP server.
|
||||
option domain_name_servers, domain_name, domain_search
|
||||
option classless_static_routes
|
||||
# Respect the network MTU. This is applied to DHCP routes.
|
||||
option interface_mtu
|
||||
|
||||
# Request a hostname from the network
|
||||
option host_name
|
||||
|
||||
# Most distributions have NTP support.
|
||||
#option ntp_servers
|
||||
|
||||
# Rapid commit support.
|
||||
# Safe to enable by default because it requires the equivalent option set
|
||||
# on the server to actually work.
|
||||
option rapid_commit
|
||||
|
||||
# A ServerID is required by RFC2131.
|
||||
require dhcp_server_identifier
|
||||
|
||||
# Generate SLAAC address using the Hardware Address of the interface
|
||||
#slaac hwaddr
|
||||
# OR generate Stable Private IPv6 Addresses based from the DUID
|
||||
slaac private
|
||||
|
||||
# Background immediately, do not wait for DHCP lease (speed up boot process)
|
||||
background
|
||||
@@ -1,144 +0,0 @@
|
||||
#
|
||||
# Run-time configuration file for dialog
|
||||
#
|
||||
# Automatically generated by "dialog --create-rc <file>"
|
||||
#
|
||||
#
|
||||
# Types of values:
|
||||
#
|
||||
# Number - <number>
|
||||
# String - "string"
|
||||
# Boolean - <ON|OFF>
|
||||
# Attribute - (foreground,background,highlight?,underline?,reverse?)
|
||||
|
||||
# Set aspect-ration.
|
||||
aspect = 0
|
||||
|
||||
# Set separator (for multiple widgets output).
|
||||
separate_widget = ""
|
||||
|
||||
# Set tab-length (for textbox tab-conversion).
|
||||
tab_len = 0
|
||||
|
||||
# Make tab-traversal for checklist, etc., include the list.
|
||||
visit_items = OFF
|
||||
|
||||
# Shadow dialog boxes? This also turns on color.
|
||||
use_shadow = ON
|
||||
|
||||
# Turn color support ON or OFF
|
||||
use_colors = ON
|
||||
|
||||
# Screen color
|
||||
screen_color = (WHITE,BLUE,OFF)
|
||||
|
||||
# Shadow color
|
||||
shadow_color = (BLACK,BLACK,OFF)
|
||||
|
||||
# Dialog box color
|
||||
dialog_color = (BLACK,CYAN,OFF)
|
||||
|
||||
# Dialog box title color
|
||||
title_color = (BLACK,CYAN,ON)
|
||||
|
||||
# Dialog box border color
|
||||
border_color = dialog_color
|
||||
|
||||
# Active button color
|
||||
button_active_color = (CYAN,BLACK,ON)
|
||||
|
||||
# Inactive button color
|
||||
button_inactive_color = dialog_color
|
||||
|
||||
# Active button key color
|
||||
button_key_active_color = (WHITE,BLACK,ON)
|
||||
|
||||
# Inactive button key color
|
||||
button_key_inactive_color = (WHITE,CYAN,ON)
|
||||
|
||||
# Active button label color
|
||||
button_label_active_color = button_active_color
|
||||
|
||||
# Inactive button label color
|
||||
button_label_inactive_color = dialog_color
|
||||
|
||||
# Input box color
|
||||
inputbox_color = (BLACK,CYAN,OFF)
|
||||
|
||||
# Input box border color
|
||||
inputbox_border_color = inputbox_color
|
||||
|
||||
# Search box color
|
||||
searchbox_color = inputbox_color
|
||||
|
||||
# Search box title color
|
||||
searchbox_title_color = (BLUE,WHITE,ON)
|
||||
|
||||
# Search box border color
|
||||
searchbox_border_color = (WHITE,WHITE,ON)
|
||||
|
||||
# File position indicator color
|
||||
position_indicator_color = searchbox_title_color
|
||||
|
||||
# Menu box color
|
||||
menubox_color = dialog_color
|
||||
|
||||
# Menu box border color
|
||||
menubox_border_color = dialog_color
|
||||
|
||||
# Item color
|
||||
item_color = inputbox_color
|
||||
|
||||
# Selected item color
|
||||
item_selected_color = button_key_active_color
|
||||
|
||||
# Tag color
|
||||
tag_color = button_inactive_color
|
||||
|
||||
# Selected tag color
|
||||
tag_selected_color = (CYAN,BLACK,OFF)
|
||||
|
||||
# Tag key color
|
||||
tag_key_color = button_key_inactive_color
|
||||
|
||||
# Selected tag key color
|
||||
tag_key_selected_color = (WHITE,BLACK,ON)
|
||||
|
||||
# Check box color
|
||||
check_color = inputbox_color
|
||||
|
||||
# Selected check box color
|
||||
check_selected_color = button_key_active_color
|
||||
|
||||
# Up arrow color
|
||||
uarrow_color = (GREEN,WHITE,ON)
|
||||
|
||||
# Down arrow color
|
||||
darrow_color = uarrow_color
|
||||
|
||||
# Item help-text color
|
||||
itemhelp_color = (WHITE,BLACK,OFF)
|
||||
|
||||
# Active form text color
|
||||
form_active_text_color = button_key_active_color
|
||||
|
||||
# Form text color
|
||||
form_text_color = (WHITE,CYAN,ON)
|
||||
|
||||
# Readonly form item color
|
||||
form_item_readonly_color = (CYAN,WHITE,ON)
|
||||
|
||||
# Dialog box gauge color
|
||||
gauge_color = searchbox_title_color
|
||||
|
||||
# Dialog box border2 color
|
||||
border2_color = dialog_color
|
||||
|
||||
# Input box border2 color
|
||||
inputbox_border2_color = inputbox_color
|
||||
|
||||
# Search box border2 color
|
||||
searchbox_border2_color = inputbox_color
|
||||
|
||||
# Menu box border2 color
|
||||
menubox_border2_color = dialog_color
|
||||
@@ -1 +0,0 @@
|
||||
run [S] /libexec/infix/swup --
|
||||
@@ -1,112 +0,0 @@
|
||||
# NetBox mdev.conf based on https://github.com/slashbeast/mdev-like-a-boss/
|
||||
|
||||
# Syntax:
|
||||
# [-]devicename_regex user:group mode [=path]|[>path]|[!] [@|$|*cmd args...]
|
||||
# [-]$ENVVAR=regex user:group mode [=path]|[>path]|[!] [@|$|*cmd args...]
|
||||
# [-]@maj,min[-min2] user:group mode [=path]|[>path]|[!] [@|$|*cmd args...]
|
||||
#
|
||||
# [-]: do not stop on this match, continue reading mdev.conf
|
||||
# =: move, >: move and create a symlink
|
||||
# !: do not create device node
|
||||
# @|$|*: run cmd if $ACTION=remove, @cmd if $ACTION=add, *cmd in all cases
|
||||
|
||||
# support module loading on hotplug
|
||||
$MODALIAS=.* root:root 660 @modprobe -b "$MODALIAS"
|
||||
|
||||
# null may already exist; therefore ownership has to be changed with command
|
||||
null root:root 666 @chmod 666 $MDEV
|
||||
zero root:root 666
|
||||
full root:root 666
|
||||
random root:root 444
|
||||
urandom root:root 444
|
||||
hwrandom root:root 444
|
||||
grsec root:root 660
|
||||
|
||||
# Kernel-based Virtual Machine.
|
||||
#kvm root:kvm 660
|
||||
|
||||
# vhost-net, to be used with kvm.
|
||||
#vhost-net root:kvm 660
|
||||
|
||||
kmem root:root 640
|
||||
mem root:root 640
|
||||
port root:root 640
|
||||
# console may already exist; therefore ownership has to be changed with command
|
||||
console root:tty 600 @chmod 600 $MDEV
|
||||
ptmx root:tty 666
|
||||
pty.* root:tty 660
|
||||
|
||||
# Typical devices
|
||||
tty root:tty 666
|
||||
tty[0-9]* root:tty 660
|
||||
vcsa*[0-9]* root:tty 660
|
||||
ttyS[0-9]* root:dialout 660
|
||||
|
||||
# block devices
|
||||
ram([0-9]*) root:disk 660 >rd/%1
|
||||
loop([0-9]+) root:disk 660 >loop/%1
|
||||
sr[0-9]* root:cdrom 660 @ln -sf $MDEV cdrom
|
||||
fd[0-9]* root:floppy 660
|
||||
#SUBSYSTEM=block;.* root:disk 660 */libexec/infix/storage-device
|
||||
|
||||
# Run settle-nics every time new NIC appear.
|
||||
# If you don't want to auto-populate /etc/mactab with NICs,
|
||||
# run 'settle-nis' without '--write-mactab' param.
|
||||
#-SUBSYSTEM=net;DEVPATH=.*/net/.*;.* root:root 600 @/libexec/infix/settle-nics --write-mactab
|
||||
|
||||
net/tun[0-9]* root:netdev 660
|
||||
net/tap[0-9]* root:root 600
|
||||
|
||||
# alsa sound devices and audio stuff
|
||||
#SUBSYSTEM=sound;.* root:audio 660 @/libexec/infix/sound-control
|
||||
|
||||
adsp root:audio 660 >sound/
|
||||
audio root:audio 660 >sound/
|
||||
dsp root:audio 660 >sound/
|
||||
mixer root:audio 660 >sound/
|
||||
sequencer.* root:audio 660 >sound/
|
||||
|
||||
|
||||
# raid controllers
|
||||
cciss!(.*) root:disk 660 =cciss/%1
|
||||
ida!(.*) root:disk 660 =ida/%1
|
||||
rd!(.*) root:disk 660 =rd/%1
|
||||
|
||||
|
||||
fuse root:root 666
|
||||
|
||||
card[0-9] root:video 660 =dri/
|
||||
|
||||
agpgart root:root 660 >misc/
|
||||
psaux root:root 660 >misc/
|
||||
rtc root:root 664 >misc/
|
||||
|
||||
# input stuff
|
||||
SUBSYSTEM=input;.* root:plugdev 660
|
||||
|
||||
# v4l stuff
|
||||
vbi[0-9] root:video 660 >v4l/
|
||||
video[0-9] root:video 660 >v4l/
|
||||
|
||||
# dvb stuff
|
||||
dvb.* root:video 660
|
||||
|
||||
# drm etc
|
||||
dri/.* root:video 660
|
||||
|
||||
# Don't create old usbdev* devices.
|
||||
usbdev[0-9].[0-9]* root:root 660 !
|
||||
|
||||
# Stop creating x:x:x:x which looks like /dev/dm-*
|
||||
[0-9]+\:[0-9]+\:[0-9]+\:[0-9]+ root:root 660 !
|
||||
|
||||
# /dev/cpu support.
|
||||
microcode root:root 600 =cpu/
|
||||
cpu([0-9]+) root:root 600 =cpu/%1/cpuid
|
||||
msr([0-9]+) root:root 600 =cpu/%1/msr
|
||||
|
||||
# Populate /dev/bus/usb.
|
||||
#SUBSYSTEM=usb;DEVTYPE=usb_device;.* root:root 660 */libexec/infix/dev-bus-usb
|
||||
|
||||
# Catch-all other devices, Right now useful only for debuging.
|
||||
#.* root:root 660 */libexec/infix/catch-all
|
||||
@@ -1 +0,0 @@
|
||||
[2m[1mNote:[0m[2m use help, show, and setup commands to set up and diagnose the system.[0m
|
||||
@@ -1,6 +0,0 @@
|
||||
# interfaces(5) file used by ifup(8) and ifdown(8)
|
||||
auto lo
|
||||
iface lo inet loopback
|
||||
|
||||
source-directory /etc/network/interfaces.d
|
||||
|
||||
@@ -1,75 +0,0 @@
|
||||
#!/usr/bin/pdmenu
|
||||
|
||||
title:Setup & Diagnostics
|
||||
|
||||
color:desktop:blue:blue
|
||||
color:title:blue:white
|
||||
color:base:blue:white
|
||||
|
||||
menu:main:Main Menu:Use arrow keys, Enter, Escape, and Q to navigate
|
||||
show:_System Settings..::system
|
||||
show:_Network Settings..::network
|
||||
show:_Tools..::tools
|
||||
nop
|
||||
exec:Show _fdb:truncate:show -p fdb
|
||||
exec:Show _mdb:truncate:show -p mdb
|
||||
exec:Show _ports:truncate:show -p ports
|
||||
exec:Show _vlans:truncate:show -p vlans
|
||||
exec:Show _interfaces:truncate:show -p iface
|
||||
exec:Show _routes:truncate:show -p route
|
||||
nop
|
||||
exec:Show _online users:truncate:w
|
||||
exec:Show _CPU Load::top
|
||||
nop
|
||||
show:_Help..::help
|
||||
exit:_Quit
|
||||
|
||||
menu:help:Help:Help Menu
|
||||
exec:Introduction:truncate:/bin/help -p
|
||||
exec:Editors:truncate:/bin/help -p edit
|
||||
exec:Networking:truncate:/bin/help -p net
|
||||
nop
|
||||
exit:_Main menu..
|
||||
|
||||
menu:network:Network:Network Settings
|
||||
exec:Show all _links:truncated:ip -br link
|
||||
exec:Show all _addresses:truncated:ip -br address
|
||||
exec:Show managed _interfaces:truncated:ifparse --all
|
||||
nop
|
||||
exec:Take _interface down:edit:ifdown ~Enter name of interface to take down:~
|
||||
exec:Take _interface up:edit:ifup ~Enter name of interface to take up:~
|
||||
nop
|
||||
exec:Edit _dhcpcd.conf::edit /etc/dhcpcd.conf
|
||||
exec:Edit _dnsmasq.conf::edit /etc/dnsmasq.conf
|
||||
exec:Edit _interfaces::edit /etc/network/interfaces
|
||||
exec:Edit _mactab::edit /etc/mactab
|
||||
exec:Edit _sysctl.conf::edit /etc/sysctl.conf
|
||||
nop
|
||||
exit:_Main menu..
|
||||
|
||||
menu:system:System:System Settings
|
||||
exec:List _log files:truncate:ls -l /var/log
|
||||
exec:Show _log file:edit,truncate:show -p -a log ~Show logfile, Enter for syslog:syslog~
|
||||
exec:Change _hostname:edit:hostnm ~Enter new hostname \[-a-zA-Z0-9\]:~
|
||||
exec:Change your _password::passwd
|
||||
exec:Edit _rc.local::edit /etc/rc.local
|
||||
nop
|
||||
exec:_Show State of Services:truncate:initctl -p
|
||||
exec:_Reload services:truncate:initctl reload;sleep 2;initctl -p
|
||||
exec:Show _available services:truncate:initctl -p ls
|
||||
exec:_Enable service:edit:initctl enable ~Enter name of service (filename) to enable:~
|
||||
exec:_Disable service:edit:initctl disable ~Enter name of service (filename) to disable:~
|
||||
nop
|
||||
exec:_Factory Reset::yorn "Factory reset device (reboots), are you sure?" factory -y
|
||||
nop
|
||||
exit:_Main menu..
|
||||
|
||||
menu:tools:Tools:Tools
|
||||
exec:_Ping:edit,pause:ping ~Enter address (IP or name) to ping:~
|
||||
exec:_Shell Prompt::/bin/bash --login
|
||||
exec:_SSH:edit,pause:ssh ~Enter [username@]address (IP or name) to SSH to:~
|
||||
exec:_Telnet:edit,pause:telnet ~Enter address (IP or name) to telnet to:~
|
||||
exec:_Traceroute:edit,pause:mtr ~Enter address (IP or name) to traceroute to:~
|
||||
exec:Browse _WWW:edit,pause:lynx ~Enter URL to browse:~
|
||||
nop
|
||||
exit:_Main menu..
|
||||
@@ -1,19 +0,0 @@
|
||||
#!/bin/sh
|
||||
# This file is run at the very end of runlevel S (bootstrap)
|
||||
#
|
||||
# Note: 1) not all initctl commands are allowed here
|
||||
# 2) to enable IP forwarding, use /etc/sysctl.conf, or /etc/sysctl.d/
|
||||
# 3) ensure the script calls `exit 0` at the end
|
||||
#
|
||||
|
||||
# Uncomment to classify all interfaces starting with 'eth' as ports.
|
||||
#for port in $(ip -br link |awk '/eth/{print $1}'); do
|
||||
# ip link set $port group port
|
||||
#done
|
||||
|
||||
# Uncomment to enable IP masquerading (NAT) of all traffic egressing
|
||||
# the WAN interface, here eth0. E.g., if you are a router for your
|
||||
# LAN on eth1.
|
||||
#iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
|
||||
|
||||
exit 0
|
||||
@@ -1,62 +0,0 @@
|
||||
#!/bin/sh
|
||||
# Factory default:
|
||||
# 1) all switch ports in VLAN 1 of br0
|
||||
# 2) no switch ports => DHCP on eth0
|
||||
# 3) no eth0
|
||||
|
||||
create_bridge()
|
||||
{
|
||||
nm=$1
|
||||
shift
|
||||
ports=$@
|
||||
|
||||
touch "/etc/network/interfaces.d/$nm"
|
||||
for port in $ports; do
|
||||
cat <<-EOF >>"/etc/network/interfaces.d/$nm"
|
||||
iface $port
|
||||
bridge-access 1
|
||||
post-up ip link set $port group port
|
||||
EOF
|
||||
done
|
||||
cat <<-EOF >> "/etc/network/interfaces.d/$nm"
|
||||
|
||||
auto $nm
|
||||
iface $nm
|
||||
bridge-ports $ports
|
||||
bridge-vlan-aware yes
|
||||
bridge-stp on
|
||||
bridge-vids 1
|
||||
|
||||
auto vlan1
|
||||
iface vlan1 inet dhcp
|
||||
vlan-id 1
|
||||
vlan-raw-device $nm
|
||||
post-up ip link set vlan1 group iface
|
||||
EOF
|
||||
ip link set vlan1 group iface
|
||||
}
|
||||
|
||||
# Check if already set up
|
||||
[ -z "$(ls -A /etc/network/interfaces.d/)" ] || exit 0
|
||||
|
||||
# Check for custom hostname from Qemu/Qeneth
|
||||
nm=$(cat /sys/firmware/qemu_fw_cfg/by_name/opt/hostname/raw)
|
||||
if [ -n "$nm" ]; then
|
||||
hostnm "$nm"
|
||||
fi
|
||||
|
||||
# need to check for 'length > 0' because ip command
|
||||
# outputs empty json objects for non-port group ifs
|
||||
ports=$(ip -json link show group port | jq -r '.[].ifname | select(length > 0)' | tr "\n" " ")
|
||||
if [ -n "$ports" ]; then
|
||||
create_bridge br0 $ports
|
||||
else
|
||||
ifaces=$(ip -json addr show |jq -r '.[] | select(.link_type=="ether").ifname')
|
||||
for iface in $ifaces; do
|
||||
cat <<-EOF > "/etc/network/interfaces.d/$iface"
|
||||
auto $iface
|
||||
iface $iface inet dhcp
|
||||
pre-up ip link set $iface group iface
|
||||
EOF
|
||||
done
|
||||
fi
|
||||
@@ -1,6 +0,0 @@
|
||||
#!/bin/sh
|
||||
# Probe for various types of harware features
|
||||
|
||||
if dmesg |grep -q QEMU || test -d /sys/module/qemu_fw_cfg; then
|
||||
initctl -nbq cond set qemu
|
||||
fi
|
||||
@@ -60,7 +60,7 @@ cat <<EOF >"$BINARIES_DIR/${NM}.gns3a"
|
||||
"status": "stable",
|
||||
"maintainer": "$VENDOR_NAME",
|
||||
"maintainer_email": "${SUPPORT_URL#mailto:}",
|
||||
"usage": "Default login, user/pass: admin/admin\n\nType 'help' for an overview of commands and relevant configuration files.\n\nFor Classic builds the following applies: the /etc directory is writable, use the passwd tool after login as part of your set up.\nFor networking, classify interfaces as switchports with /etc/mactab, syntax: 'MAC-address eN', where N is the port number (1-MAX).\nTo set up bridging and management interfaces, use /etc/network/interfaces, and /etc/network/interfaces.d/",
|
||||
"usage": "Default login, user/pass: admin/admin\n\nType 'cli' (and Enter) followed by 'help' for an overview of commands and relevant configuration files.",
|
||||
"port_name_format": "eth{0}",
|
||||
"linked_clone": true,
|
||||
"qemu": {
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
#!/bin/sh
|
||||
# shellcheck disable=SC1090,SC1091
|
||||
common=$(dirname "$(readlink -f "$0")")
|
||||
. "$BR2_CONFIG" 2>/dev/null
|
||||
. "$TARGET_DIR/usr/lib/os-release"
|
||||
|
||||
@@ -31,6 +32,7 @@ rm -f "$TARGET_DIR/etc/os-release"
|
||||
echo "ID=$INFIX_ID"
|
||||
echo "PRETTY_NAME=\"$INFIX_TAGLINE $VERSION\""
|
||||
echo "ID_LIKE=\"${ID}\""
|
||||
echo "DEFAULT_HOSTNAME=$BR2_TARGET_GENERIC_HOSTNAME"
|
||||
echo "VERSION=\"${VERSION}\""
|
||||
echo "VERSION_ID=${VERSION}"
|
||||
echo "BUILD_ID=\"${GIT_VERSION}\""
|
||||
@@ -40,13 +42,6 @@ rm -f "$TARGET_DIR/etc/os-release"
|
||||
if [ -n "$INFIX_RELEASE" ]; then
|
||||
echo "IMAGE_VERSION=\"$INFIX_RELEASE\""
|
||||
fi
|
||||
if [ "$INFIX_VARIANT_NETCONF" = "y" ]; then
|
||||
echo "VARIANT=\"Managed NETCONF\""
|
||||
echo "VARIANT_ID=netconf"
|
||||
else
|
||||
echo "VARIANT=\"Classic, writable /etc\""
|
||||
echo "VARIANT_ID=classic"
|
||||
fi
|
||||
echo "ARCHITECTURE=\"${INFIX_ARCH}\""
|
||||
echo "HOME_URL=$INFIX_HOME"
|
||||
if [ -n "$INFIX_VENDOR" ]; then
|
||||
@@ -68,6 +63,12 @@ rm -f "$TARGET_DIR/etc/os-release"
|
||||
|
||||
echo "$INFIX_TAGLINE $VERSION -- $(date +"%b %e %H:%M %Z %Y")" > "$TARGET_DIR/etc/version"
|
||||
|
||||
# Drop Buildroot default symlink to /tmp
|
||||
if [ -L "$TARGET_DIR/var/lib/avahi-autoipd" ]; then
|
||||
rm "$TARGET_DIR/var/lib/avahi-autoipd"
|
||||
mkdir "$TARGET_DIR/var/lib/avahi-autoipd"
|
||||
fi
|
||||
|
||||
# Allow pdmenu (setup) and bash to be login shells, bash is added
|
||||
# automatically when selected in menuyconfig, but not when BusyBox
|
||||
# provides a symlink (for ash). The /bin/{true,false} are old UNIX
|
||||
@@ -80,3 +81,7 @@ grep -qsE '^/bin/true$$' "$TARGET_DIR/etc/shells" \
|
||||
|| echo "/bin/true" >> "$TARGET_DIR/etc/shells"
|
||||
grep -qsE '^/bin/false$$' "$TARGET_DIR/etc/shells" \
|
||||
|| echo "/bin/false" >> "$TARGET_DIR/etc/shells"
|
||||
|
||||
# Allow clish (symlink to /usr/bin/klish) to be a login shell
|
||||
grep -qsE '^/bin/clish$$' "$TARGET_DIR/etc/shells" \
|
||||
|| echo "/bin/clish" >> "$TARGET_DIR/etc/shells"
|
||||
|
||||
@@ -63,8 +63,8 @@ endchoice
|
||||
|
||||
config QEMU_MACHINE
|
||||
string "Select emulated machine"
|
||||
default "qemu-system-aarch64 -M virt -cpu cortex-a72" if QEMU_aarch64
|
||||
default "qemu-system-x86_64 -M q35,accel=kvm -cpu host" if QEMU_x86_64
|
||||
default "qemu-system-aarch64 -M virt,accel=kvm:tcg -cpu max" if QEMU_aarch64
|
||||
default "qemu-system-x86_64 -M pc,accel=kvm:tcg -cpu max" if QEMU_x86_64
|
||||
help
|
||||
You should not have to change this setting, although you may
|
||||
want to tweak it, or change the acceleration.
|
||||
@@ -77,9 +77,9 @@ config QEMU_MACHINE_RAM
|
||||
string "RAM size (k/M/G)"
|
||||
default "384M"
|
||||
help
|
||||
The default, 384 MiB, works for most configurations, even less for
|
||||
the Infix Classic builds. However, if you get kernel panic with:
|
||||
"System is deadlocked on memory", try increasing this one.
|
||||
The default, 384 MiB, works for most configurations. However,
|
||||
if you get kernel panic with: "System is deadlocked on memory",
|
||||
try increasing this one.
|
||||
|
||||
config QEMU_KERNEL
|
||||
string
|
||||
|
||||
Executable
+67
@@ -0,0 +1,67 @@
|
||||
#!/usr/bin/env python3
|
||||
# Generate a self signed certificate with unlimited expire time
|
||||
|
||||
import argparse
|
||||
|
||||
from cryptography import x509
|
||||
from cryptography.x509.oid import NameOID
|
||||
from cryptography.hazmat.primitives import hashes, serialization
|
||||
from cryptography.hazmat.primitives.asymmetric import rsa
|
||||
from cryptography.hazmat.backends import default_backend
|
||||
from datetime import datetime, timedelta
|
||||
|
||||
# Generate private key
|
||||
private_key = rsa.generate_private_key(
|
||||
public_exponent=65537,
|
||||
key_size=2048,
|
||||
backend=default_backend()
|
||||
|
||||
)
|
||||
|
||||
parser = argparse.ArgumentParser(description="Generate a self signed certificate")
|
||||
parser.add_argument('--country', required=True, help="Set country")
|
||||
parser.add_argument('--state', required=True, help="Set state or province name")
|
||||
parser.add_argument('--city', required=True, help="Set city name")
|
||||
parser.add_argument('--organisation', required=True, help="Set organisation name")
|
||||
parser.add_argument('--organisation-unit', required=True, help="Set organisation unit name")
|
||||
parser.add_argument('--common-name', required=True, help="Set common name")
|
||||
parser.add_argument('--out-certificate', required=True, help="Output certificate")
|
||||
parser.add_argument('--out-key', required=True, help="Output key")
|
||||
|
||||
args = parser.parse_args()
|
||||
|
||||
# Builder for certificate
|
||||
subject = issuer = x509.Name([
|
||||
x509.NameAttribute(NameOID.COUNTRY_NAME, args.country),
|
||||
x509.NameAttribute(NameOID.STATE_OR_PROVINCE_NAME, args.state),
|
||||
x509.NameAttribute(NameOID.LOCALITY_NAME, args.city),
|
||||
x509.NameAttribute(NameOID.ORGANIZATION_NAME, args.organisation),
|
||||
x509.NameAttribute(NameOID.ORGANIZATIONAL_UNIT_NAME, args.organisation_unit),
|
||||
x509.NameAttribute(NameOID.COMMON_NAME, args.common_name),
|
||||
])
|
||||
certificate = x509.CertificateBuilder().subject_name(
|
||||
subject
|
||||
).issuer_name(
|
||||
issuer
|
||||
).public_key(
|
||||
private_key.public_key()
|
||||
).serial_number(
|
||||
x509.random_serial_number()
|
||||
).not_valid_before(
|
||||
datetime(2000, 1, 1)
|
||||
).not_valid_after(
|
||||
datetime(9999, 1, 1)
|
||||
).add_extension(
|
||||
x509.SubjectAlternativeName([x509.DNSName(args.common_name)]),
|
||||
critical=False,
|
||||
).sign(private_key, hashes.SHA256(), default_backend())
|
||||
|
||||
# Serialize certificate and private key
|
||||
with open(args.out_certificate, "wb") as f:
|
||||
f.write(certificate.public_bytes(serialization.Encoding.PEM))
|
||||
with open(args.out_key, "wb") as f:
|
||||
f.write(private_key.private_bytes(
|
||||
encoding=serialization.Encoding.PEM,
|
||||
format=serialization.PrivateFormat.PKCS8,
|
||||
encryption_algorithm=serialization.NoEncryption()
|
||||
))
|
||||
Executable
+5
@@ -0,0 +1,5 @@
|
||||
#!/bin/sh
|
||||
|
||||
sleep 30
|
||||
|
||||
stress-ng --cpu 8 --io 4 --vm 2 --vm-bytes 128M --fork 4 -t 0
|
||||
Executable
+76
@@ -0,0 +1,76 @@
|
||||
#!/bin/sh
|
||||
|
||||
tstamp()
|
||||
{
|
||||
if [ "$1" = "head" ]; then
|
||||
printf '%9s' time
|
||||
else
|
||||
printf '%9s' $(date +%T)
|
||||
fi
|
||||
}
|
||||
|
||||
thermal()
|
||||
{
|
||||
for th in /sys/class/thermal/thermal_zone*; do
|
||||
if [ "$1" = "head" ]; then
|
||||
printf '%5s' $(cat $th/type | \
|
||||
sed -e 's/-thermal//' -e 's/ap-cpu/cpu/' -e 's/-ic//')
|
||||
else
|
||||
printf '%5d' \
|
||||
$((($(cat $th/temp) + 500) / 1000))
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
|
||||
hwmon()
|
||||
{
|
||||
for hw in /sys/class/hwmon/*; do
|
||||
[ -f $hw/temp1_input ] || continue
|
||||
|
||||
if [ "$1" = "head" ]; then
|
||||
printf '%5s' \
|
||||
$(cat $hw/name | sed -e 's/cp0configspacef2000000mdio12a200switch0mdio0/p/' -e 's/f212a600mdiomii0/xp/')
|
||||
else
|
||||
printf '%5d' \
|
||||
$((($(cat $hw/temp1_input) + 500) / 1000))
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
xphys()
|
||||
{
|
||||
for xphy in 4 5; do
|
||||
mdio f212a6* $xphy:31 0xf08a 0x4d00
|
||||
|
||||
if [ "$1" = "head" ]; then
|
||||
printf '%5s' \
|
||||
p$((xphy + 5))
|
||||
else
|
||||
printf '%5d' \
|
||||
$(($(mdio f212a6* $xphy:31 0xf08a) & 0xff - 75))
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
if [ "$1" != "-H" ]; then
|
||||
# tstamp head
|
||||
thermal head
|
||||
hwmon head
|
||||
# xphys head
|
||||
echo
|
||||
fi
|
||||
|
||||
while :; do
|
||||
# tstamp
|
||||
thermal
|
||||
hwmon
|
||||
# xphys
|
||||
echo
|
||||
|
||||
if [ "$1" == "-n" ]; then
|
||||
sleep ${2:-10}
|
||||
else
|
||||
break
|
||||
fi
|
||||
done
|
||||
@@ -43,7 +43,7 @@ if [ -x /bin/ip -o -x /sbin/ip ] ; then
|
||||
BIND)
|
||||
ip addr flush dev "$2" label "$2:avahi"
|
||||
ip addr add "$3"/16 brd 169.254.255.255 label "$2:avahi" scope link dev "$2" proto 6
|
||||
ip route add default dev "$2" metric "$METRIC" scope link ||:
|
||||
ip route add default dev "$2" metric "$METRIC" scope link proto zeroconf ||:
|
||||
;;
|
||||
|
||||
CONFLICT|UNBIND|STOP)
|
||||
|
||||
@@ -2,8 +2,12 @@
|
||||
# managed by openresolv. DHCP lease, VPN tunnel establishment,
|
||||
# and similar events feed servers and configuration to dnsmasq.
|
||||
domain-needed
|
||||
#interface=lo
|
||||
listen-address=127.0.0.1
|
||||
|
||||
# Only listen to loopback (local system)
|
||||
interface=lo
|
||||
bind-dynamic
|
||||
#listen-address=127.0.0.1,::1
|
||||
|
||||
enable-dbus
|
||||
|
||||
# Generated by openresolv
|
||||
|
||||
@@ -1 +1,2 @@
|
||||
set COLORTERM=yes
|
||||
rlimit soft core infinity
|
||||
@@ -0,0 +1 @@
|
||||
task [S] <service/confd/ready> /libexec/infix/mkcert -- Verifying self-signed https certificate
|
||||
@@ -0,0 +1,3 @@
|
||||
service [2345789] log:/var/log/temp.log /bin/temp.sh -n 10 -- Temperature monitor
|
||||
service [2345789] log:/var/log/load.log /bin/load.sh -- CPU load generator
|
||||
service [2345789] log:/var/log/memtester.log /usr/bin/memtester 1G -- Memory load generator
|
||||
@@ -0,0 +1 @@
|
||||
service [2345] <!> ttyd -i lo -p 8001 login -- Web terminal daemon (ttyd)
|
||||
@@ -0,0 +1 @@
|
||||
../available/mkcert.conf
|
||||
@@ -0,0 +1 @@
|
||||
../available/temp.conf
|
||||
@@ -0,0 +1,6 @@
|
||||
# Sourced by mkcert at boot
|
||||
country=SE
|
||||
state=Vastmanland
|
||||
city=Vasteras
|
||||
org=KernelKit
|
||||
unit=Infix
|
||||
@@ -0,0 +1,27 @@
|
||||
server {
|
||||
listen 80;
|
||||
listen [::]:80;
|
||||
server_name _;
|
||||
return 301 https://$host$request_uri;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl;
|
||||
listen [::]:443 ssl;
|
||||
server_name _;
|
||||
include ssl.conf;
|
||||
|
||||
#error_page 404 /404.html;
|
||||
|
||||
# redirect server error pages to the static page /50x.html
|
||||
#
|
||||
error_page 500 502 503 504 /50x.html;
|
||||
location = /50x.html {
|
||||
root html;
|
||||
}
|
||||
|
||||
location / {
|
||||
root html;
|
||||
index index.html index.htm;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,18 @@
|
||||
server {
|
||||
listen 443 ssl;
|
||||
listen [::]:443 ssl;
|
||||
server_name network.local;
|
||||
include ssl.conf;
|
||||
|
||||
location / {
|
||||
proxy_pass http://127.0.0.1:8000;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection 'upgrade';
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_redirect off;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,19 @@
|
||||
server {
|
||||
listen 7681 ssl;
|
||||
listen [::]:7681 ssl;
|
||||
server_name _;
|
||||
|
||||
include ssl.conf;
|
||||
|
||||
location / {
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_pass http://127.0.0.1:8001;
|
||||
proxy_redirect off;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1 @@
|
||||
../available/default.conf
|
||||
@@ -0,0 +1,24 @@
|
||||
user www-data www-data;
|
||||
worker_processes 1;
|
||||
|
||||
events {
|
||||
worker_connections 1024;
|
||||
}
|
||||
|
||||
http {
|
||||
include mime.types;
|
||||
default_type application/octet-stream;
|
||||
|
||||
sendfile on;
|
||||
#tcp_nopush on;
|
||||
|
||||
#keepalive_timeout 0;
|
||||
keepalive_timeout 65;
|
||||
|
||||
#gzip on;
|
||||
|
||||
include /etc/nginx/enabled/*.conf;
|
||||
|
||||
access_log syslog:server=unix:/dev/log,nohostname,facility=local7,severity=info;
|
||||
error_log syslog:server=unix:/dev/log,nohostname,facility=local7 info;
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
ssl_certificate /etc/ssl/certs/self-signed.crt;
|
||||
ssl_certificate_key /etc/ssl/private/self-signed.key;
|
||||
|
||||
ssl_protocols TLSv1.3 TLSv1.2;
|
||||
ssl_ciphers HIGH:!aNULL:!MD5;
|
||||
ssl_prefer_server_ciphers on;
|
||||
|
||||
ssl_session_cache shared:SSL:1m;
|
||||
ssl_session_timeout 5m;
|
||||
@@ -0,0 +1 @@
|
||||
kernel.core_pattern=/var/crash/core-%e
|
||||
Executable
+42
@@ -0,0 +1,42 @@
|
||||
#!/bin/sh
|
||||
|
||||
KEY=/cfg/ssl/private/self-signed.key
|
||||
CRT=/cfg/ssl/certs/self-signed.crt
|
||||
|
||||
country=US
|
||||
state=California
|
||||
city=Berkeley
|
||||
org="Acme, Inc."
|
||||
unit=Second
|
||||
|
||||
if [ -f /etc/mkcert.conf ]; then
|
||||
. /etc/mkcert.conf
|
||||
fi
|
||||
|
||||
if [ -z "$cn" ]; then
|
||||
cn=$1
|
||||
if [ -z "$cn" ]; then
|
||||
cn=$(hostname).local
|
||||
fi
|
||||
fi
|
||||
|
||||
generate()
|
||||
{
|
||||
mkdir -p /cfg/ssl/private /cfg/ssl/certs
|
||||
chmod 700 /cfg/ssl/private
|
||||
|
||||
gencert --country "$country" --state "$state" --city "$city" --organisation "$org" \
|
||||
--organisation-unit "$unit" --common-name "$cn" \
|
||||
--out-certificate $CRT --out-key $KEY
|
||||
}
|
||||
|
||||
CN=$(openssl x509 -noout -subject -in "${CRT}" 2>/dev/null |sed 's/.*CN=//')
|
||||
if [ -z "$CN" ] || [ "$CN" != "$cn" ]; then
|
||||
generate "$cn"
|
||||
fi
|
||||
|
||||
cp "${KEY}" "/etc/ssl/private/"
|
||||
cp "${CRT}" "/etc/ssl/certs/"
|
||||
initctl cond set mkcert
|
||||
|
||||
exit 0
|
||||
@@ -126,11 +126,6 @@ if ! mount_rw cfg >/dev/null 2>&1; then
|
||||
# Even if /mnt/var isn't available, if /mnt/cfg isn't either, then
|
||||
# there's no point in overlaying one ramdisk on top of another.
|
||||
vlibsrc=
|
||||
else
|
||||
# Classic Infix has read-write /etc across boots
|
||||
if [ "$VARIANT_ID" != "netconf" ]; then
|
||||
etcsrc=/mnt/cfg
|
||||
fi
|
||||
fi
|
||||
|
||||
if check_factory; then
|
||||
|
||||
+1
-1
@@ -8,7 +8,7 @@ bootoffs=$2
|
||||
bootsize=8M
|
||||
auxsize=8M
|
||||
|
||||
total=$(awk -vdisk="$(basename $disk)" '$4 == disk { print($3 / 1024); }' /proc/partitions)
|
||||
total=$(awk -vdisk="$(basename $disk)" '$4 == disk { print(int($3 / 1024)); }' /proc/partitions)
|
||||
if [ "$total" -ge 4096 ]; then
|
||||
imgsize=1024M
|
||||
cfgsize=512M
|
||||
@@ -0,0 +1,15 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Error</title>
|
||||
<style>
|
||||
html { color-scheme: light dark; }
|
||||
body { width: 35em; margin: 0 auto;
|
||||
font-family: Tahoma, Verdana, Arial, sans-serif; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<h1>An error occurred.</h1>
|
||||
<p>Sorry, the page you are looking for is currently unavailable.</p>
|
||||
</body>
|
||||
</html>
|
||||
Executable
+12
@@ -0,0 +1,12 @@
|
||||
#!/bin/sh
|
||||
# Generate index.html from Infix README.md
|
||||
|
||||
BASE=../../../../..
|
||||
TITLE="Welcome to Infix :-)"
|
||||
|
||||
cp $BASE/doc/logo.png .
|
||||
cat $BASE/README.md \
|
||||
| tail +2 \
|
||||
| sed 's/doc\/logo.png/logo.png/' \
|
||||
| pandoc -f markdown+implicit_figures+link_attributes -o index.html \
|
||||
--metadata pagetitle="$TITLE" --template=hpstr-template.html
|
||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
Binary file not shown.
|
After Width: | Height: | Size: 16 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 20 KiB |
@@ -103,8 +103,8 @@ create()
|
||||
logging="--log-driver k8s-file --log-opt path=/run/containers/$name.fifo"
|
||||
fi
|
||||
|
||||
args="$args --cgroup-parent=containers"
|
||||
args="$args --restart=$restart --systemd=false --tz=local $privileged --replace --quiet"
|
||||
args="$args --replace --quiet --cgroup-parent=containers $caps"
|
||||
args="$args --restart=$restart --systemd=false --tz=local $privileged"
|
||||
args="$args $ro $vol $mount $hostname $entrypoint $env $port $logging"
|
||||
pidfn=/run/container:${name}.pid
|
||||
|
||||
@@ -125,10 +125,11 @@ create()
|
||||
args="$args --dns-search=$domain"
|
||||
done
|
||||
else
|
||||
network="--net none"
|
||||
args="$args --network=none"
|
||||
fi
|
||||
|
||||
# shellcheck disable=SC2048
|
||||
log "Calling podman create --name $name --conmon-pidfile=$pidfn $args $image $*"
|
||||
if podman create --name "$name" --conmon-pidfile="$pidfn" $args "$image" $*; then
|
||||
[ -n "$quiet" ] || log "Successfully created container $name from $image"
|
||||
rm -f "/run/containers/env/${name}.env"
|
||||
@@ -216,6 +217,20 @@ netwrm()
|
||||
done
|
||||
}
|
||||
|
||||
# Schedule restart of (any) container using network $1 to activate network changes
|
||||
netrestart()
|
||||
{
|
||||
net=$1
|
||||
|
||||
for c in $(podman ps $all --format "{{.Names}}"); do
|
||||
for n in $(podman inspect "$c" |jq -r '.[].NetworkSettings.Networks | keys[]'); do
|
||||
if [ "$n" = "$net" ]; then
|
||||
initctl -nbq touch "container@$c"
|
||||
fi
|
||||
done
|
||||
done
|
||||
}
|
||||
|
||||
usage()
|
||||
{
|
||||
cat <<EOF
|
||||
@@ -226,6 +241,8 @@ options:
|
||||
-a, --all Show all, of something
|
||||
--dns NAMESERVER Set nameserver(s) when creating a container
|
||||
--dns-search LIST Set host lookup search list when creating container
|
||||
--cap-add CAP Add capability to unprivileged container
|
||||
--cap-drop CAP Drop capability, for privileged containter
|
||||
-c, --creds USR[:PWD] Credentials to pass to curl -u for remote ops
|
||||
-d, --detach Detach a container started with 'run IMG [CMD]'
|
||||
-e, --env FILE Environment variables when creating container
|
||||
@@ -259,7 +276,7 @@ commands:
|
||||
list [image | oci] List names (only) of containers, images, or OCI archives
|
||||
load [NAME | URL] NM Load OCI tarball fileNAME or URL to image NM
|
||||
remove IMAGE Remove an (unused) container image
|
||||
restart [NAME] Restart a crashed container
|
||||
restart [network] NAME Restart a (crashed) container or container(s) using network
|
||||
run NAME [CMD] Run a container interactively, with an optional command
|
||||
save IMAGE FILE Save a container image to an OCI tarball FILE[.tar.gz]
|
||||
shell Start a shell inside a container
|
||||
@@ -276,6 +293,14 @@ while [ "$1" != "" ]; do
|
||||
-a | --all)
|
||||
all="-a"
|
||||
;;
|
||||
--cap-add)
|
||||
shift
|
||||
caps="$caps --cap-add=$1"
|
||||
;;
|
||||
--cap-drop)
|
||||
shift
|
||||
caps="$caps --cap-drop=$1"
|
||||
;;
|
||||
-c | --creds)
|
||||
shift
|
||||
creds="-u $1"
|
||||
@@ -541,8 +566,24 @@ case $cmd in
|
||||
if [ -n "$name" ]; then
|
||||
wrap "$name" restart
|
||||
elif [ -n "$1" ]; then
|
||||
stop "$1"
|
||||
start "$1"
|
||||
cmd=$1
|
||||
name=$2
|
||||
if [ "$cmd" = "network" ] && [ -n "$name" ]; then
|
||||
netrestart "$name"
|
||||
else
|
||||
name=$1
|
||||
stop "$name"
|
||||
timeout=20
|
||||
while running "$name"; do
|
||||
_=$((timeoute -= 1))
|
||||
if [ $timeout -le 0 ]; then
|
||||
log "Timeout waiting for container $1 to stop before restarting it."
|
||||
exit 1
|
||||
fi
|
||||
sleep 1
|
||||
done
|
||||
start "$name"
|
||||
fi
|
||||
else
|
||||
usage
|
||||
exit 1
|
||||
@@ -567,8 +608,14 @@ case $cmd in
|
||||
echo "No such container ($1), or invalid ImageName. Cannot upgrade."
|
||||
exit 1;
|
||||
fi
|
||||
podman stop "$1"
|
||||
podman pull "$img" || (echo "Failed fetching $img, check your network (settings)."; exit 1)
|
||||
if echo "$img" | grep -Eq '^localhost/'; then
|
||||
# Likely an OCI archive, or local directory, assume user has updated image.
|
||||
file=$(awk '{s=$NF} END{print s}' "/var/lib/containers/active/${1}.sh")
|
||||
echo "Upgrading container ${1} with local archive: $file ..."
|
||||
else
|
||||
podman stop "$1"
|
||||
podman pull "$img" || (echo "Failed fetching $img, check your network (settings)."; exit 1)
|
||||
fi
|
||||
"/var/lib/containers/active/${1}.sh" || (echo "Failed recreating container $1"; exit 1)
|
||||
;;
|
||||
volume)
|
||||
|
||||
@@ -1,3 +1,5 @@
|
||||
# Allow users in wheel group to reboot and perform a factory reset
|
||||
/sbin/initctl f 4750 root wheel - - - - -
|
||||
/sbin/factory f 4750 root wheel - - - - -
|
||||
|
||||
/var/lib/avahi-autoipd d 0755 avahi avahi - - - - -
|
||||
|
||||
@@ -1,13 +0,0 @@
|
||||
#!/bin/sh
|
||||
# shellcheck disable=SC1090
|
||||
. "$BR2_CONFIG" 2>/dev/null
|
||||
|
||||
# Drop Buildroot default symlink to /tmp
|
||||
if [ -L "$TARGET_DIR/var/lib/avahi-autoipd" ]; then
|
||||
rm "$TARGET_DIR/var/lib/avahi-autoipd"
|
||||
mkdir "$TARGET_DIR/var/lib/avahi-autoipd"
|
||||
fi
|
||||
|
||||
# Allow clish (symlink to /usr/bin/klish) to be a login shell
|
||||
grep -qsE '^/bin/clish$$' "$TARGET_DIR/etc/shells" \
|
||||
|| echo "/bin/clish" >> "$TARGET_DIR/etc/shells"
|
||||
@@ -1,88 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
# This file is part of avahi.
|
||||
#
|
||||
# avahi is free software; you can redistribute it and/or modify it
|
||||
# under the terms of the GNU Lesser General Public License as
|
||||
# published by the Free Software Foundation; either version 2 of the
|
||||
# License, or (at your option) any later version.
|
||||
#
|
||||
# avahi is distributed in the hope that it will be useful, but WITHOUT
|
||||
# ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
# or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public
|
||||
# License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU Lesser General Public
|
||||
# License along with avahi; if not, write to the Free Software
|
||||
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307
|
||||
# USA.
|
||||
|
||||
set -e
|
||||
|
||||
# Command line arguments:
|
||||
# $1 event that happened:
|
||||
# BIND: Successfully claimed address
|
||||
# CONFLICT: An IP address conflict happened
|
||||
# UNBIND: The IP address is no longer needed
|
||||
# STOP: The daemon is terminating
|
||||
# $2 interface name
|
||||
# $3 IP adddress
|
||||
|
||||
PATH="$PATH:/usr/bin:/usr/sbin:/bin:/sbin"
|
||||
|
||||
# Use a different metric for each interface, so that we can set
|
||||
# identical routes to multiple interfaces.
|
||||
|
||||
METRIC=$((1000 + `cat "/sys/class/net/$2/ifindex" 2>/dev/null || echo 0`))
|
||||
|
||||
if [ -x /bin/ip -o -x /sbin/ip ] ; then
|
||||
|
||||
# We have the Linux ip tool from the iproute package
|
||||
|
||||
case "$1" in
|
||||
BIND)
|
||||
ip addr flush dev "$2" label "$2:avahi"
|
||||
ip addr add "$3"/16 brd 169.254.255.255 label "$2:avahi" scope link dev "$2" proto 6
|
||||
ip route add default dev "$2" metric "$METRIC" scope link proto 17 ||:
|
||||
;;
|
||||
|
||||
CONFLICT|UNBIND|STOP)
|
||||
ip route del default dev "$2" metric "$METRIC" scope link ||:
|
||||
ip addr del "$3"/16 brd 169.254.255.255 label "$2:avahi" scope link dev "$2"
|
||||
;;
|
||||
|
||||
*)
|
||||
echo "Unknown event $1" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
elif [ -x /bin/ifconfig -o -x /sbin/ifconfig ] ; then
|
||||
|
||||
# We have the old ifconfig tool
|
||||
|
||||
case "$1" in
|
||||
BIND)
|
||||
ifconfig "$2:avahi" inet "$3" netmask 255.255.0.0 broadcast 169.254.255.255 up
|
||||
route add default dev "$2:avahi" metric "$METRIC" ||:
|
||||
;;
|
||||
|
||||
CONFLICT|STOP|UNBIND)
|
||||
route del default dev "$2:avahi" metric "$METRIC" ||:
|
||||
ifconfig "$2:avahi" down
|
||||
;;
|
||||
|
||||
*)
|
||||
echo "Unknown event $1" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
else
|
||||
|
||||
echo "No network configuration tool found." >&2
|
||||
exit 1
|
||||
|
||||
fi
|
||||
|
||||
exit 0
|
||||
@@ -1 +0,0 @@
|
||||
/var/lib/avahi-autoipd d 0755 avahi avahi - - - - -
|
||||
@@ -29,4 +29,4 @@ test-run-play: | ~/.infix-test-venv
|
||||
~/.infix-test-venv:
|
||||
$(test-dir)/docker/init-venv.sh $(test-dir)/docker/pip-requirements.txt
|
||||
|
||||
.PHONY: test-unit test test-sh test-qeneth test-qeneth-sh test-run test-run-sh test-run-play
|
||||
.PHONY: test test-sh test-qeneth test-qeneth-sh test-run test-run-sh test-run-play
|
||||
|
||||
+1
-1
Submodule buildroot updated: f5435bd048...d49f1e9e90
@@ -1,120 +0,0 @@
|
||||
BR2_aarch64=y
|
||||
BR2_ARM_FPU_VFPV4=y
|
||||
BR2_TOOLCHAIN_EXTERNAL=y
|
||||
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
|
||||
BR2_TOOLCHAIN_EXTERNAL_GDB_SERVER_COPY=y
|
||||
BR2_DL_DIR="${BR2_EXTERNAL_INFIX_PATH}/dl"
|
||||
BR2_CCACHE=y
|
||||
BR2_CCACHE_DIR="${BR2_EXTERNAL_INFIX_PATH}/.ccache"
|
||||
BR2_ENABLE_DEBUG=y
|
||||
BR2_GLOBAL_PATCH_DIR="${BR2_EXTERNAL_INFIX_PATH}/patches"
|
||||
BR2_TARGET_GENERIC_HOSTNAME="infix"
|
||||
BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_MDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
BR2_SYSTEM_DHCP="eth0"
|
||||
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA"
|
||||
BR2_GENERATE_LOCALE="en_US en_CA"
|
||||
BR2_TARGET_TZ_INFO=y
|
||||
BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/classic/rootfs"
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/classic/post-build.sh"
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.11"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_DTS_SUPPORT=y
|
||||
BR2_LINUX_KERNEL_INTREE_DTS_NAME="alder/alder marvell/armada-3720-espressobin marvell/armada-3720-espressobin-emmc marvell/armada-3720-espressobin-v7 marvell/armada-3720-espressobin-v7-emmc marvell/armada-3720-espressobin-ultra marvell/cn9130-crb-A marvell/cn9130-crb-B microchip/sparx5_pcb135_emmc_no_psci"
|
||||
BR2_LINUX_KERNEL_CUSTOM_DTS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/dts"
|
||||
BR2_LINUX_KERNEL_DTB_KEEP_DIRNAME=y
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
||||
BR2_PACKAGE_BUSYBOX_SHOW_OTHERS=y
|
||||
BR2_PACKAGE_STRACE=y
|
||||
BR2_PACKAGE_STRESS_NG=y
|
||||
BR2_PACKAGE_JQ=y
|
||||
BR2_PACKAGE_MDIO_TOOLS=y
|
||||
BR2_PACKAGE_RNG_TOOLS=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_FIT_CHECK_SIGN=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_MKENVIMAGE=y
|
||||
BR2_PACKAGE_CA_CERTIFICATES=y
|
||||
BR2_PACKAGE_LIBCURL_CURL=y
|
||||
BR2_PACKAGE_NSS_MDNS=y
|
||||
BR2_PACKAGE_ONIGURUMA=y
|
||||
BR2_PACKAGE_AVAHI=y
|
||||
# BR2_PACKAGE_AVAHI_AUTOIPD is not set
|
||||
BR2_PACKAGE_AVAHI_DAEMON=y
|
||||
BR2_PACKAGE_AVAHI_DEFAULT_SERVICES=y
|
||||
BR2_PACKAGE_CHRONY=y
|
||||
BR2_PACKAGE_DHCPCD=y
|
||||
BR2_PACKAGE_DNSMASQ=y
|
||||
BR2_PACKAGE_DROPBEAR=y
|
||||
BR2_PACKAGE_DROPBEAR_DISABLE_REVERSEDNS=y
|
||||
BR2_PACKAGE_DROPBEAR_WTMP=y
|
||||
BR2_PACKAGE_DROPBEAR_LASTLOG=y
|
||||
BR2_PACKAGE_DROPBEAR_LEGACY_CRYPTO=y
|
||||
BR2_PACKAGE_ETHTOOL=y
|
||||
BR2_PACKAGE_FPING=y
|
||||
# BR2_PACKAGE_IFUPDOWN_SCRIPTS is not set
|
||||
BR2_PACKAGE_IPROUTE2=y
|
||||
BR2_PACKAGE_IPTABLES=y
|
||||
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_LYNX=y
|
||||
BR2_PACKAGE_MTR=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NFTABLES=y
|
||||
BR2_PACKAGE_NMAP=y
|
||||
BR2_PACKAGE_NMAP_NMAP=y
|
||||
BR2_PACKAGE_NMAP_NPING=y
|
||||
BR2_PACKAGE_OPENRESOLV=y
|
||||
BR2_PACKAGE_SOCAT=y
|
||||
BR2_PACKAGE_TCPDUMP=y
|
||||
BR2_PACKAGE_TRACEROUTE=y
|
||||
BR2_PACKAGE_DIALOG=y
|
||||
BR2_PACKAGE_PDMENU=y
|
||||
BR2_PACKAGE_HTOP=y
|
||||
BR2_PACKAGE_IRQBALANCE=y
|
||||
BR2_PACKAGE_KMOD_TOOLS=y
|
||||
BR2_PACKAGE_PWGEN=y
|
||||
BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
BR2_PACKAGE_MG=y
|
||||
BR2_PACKAGE_MOST=y
|
||||
BR2_PACKAGE_NANO=y
|
||||
BR2_TARGET_ROOTFS_SQUASHFS=y
|
||||
# BR2_TARGET_ROOTFS_TAR is not set
|
||||
BR2_PACKAGE_HOST_E2FSPROGS=y
|
||||
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
||||
BR2_PACKAGE_HOST_GENEXT2FS=y
|
||||
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||
BR2_PACKAGE_HOST_RAUC=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||
INFIX_VARIANT_CLASSIC=y
|
||||
BR2_PACKAGE_FACTORY=y
|
||||
BR2_PACKAGE_FINIT_SULOGIN=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_MODULES_LOAD=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_MODPROBE=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_RTC=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
||||
BR2_PACKAGE_IFUPDOWN_NG=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
@@ -12,20 +12,19 @@ BR2_TARGET_GENERIC_HOSTNAME="infix"
|
||||
BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/xattrs"
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||
BR2_SYSTEM_BIN_SH_BASH=y
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
BR2_SYSTEM_DHCP="eth0"
|
||||
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA"
|
||||
BR2_GENERATE_LOCALE="en_US en_CA"
|
||||
BR2_TARGET_TZ_INFO=y
|
||||
BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/rootfs"
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/post-build.sh"
|
||||
BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/rootfs"
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.11"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.22"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_DTS_SUPPORT=y
|
||||
@@ -46,6 +45,7 @@ BR2_PACKAGE_EUDEV_RULES_GEN=y
|
||||
BR2_PACKAGE_GPTFDISK=y
|
||||
BR2_PACKAGE_GPTFDISK_SGDISK=y
|
||||
BR2_PACKAGE_MDIO_TOOLS=y
|
||||
BR2_PACKAGE_MEMTESTER=y
|
||||
BR2_PACKAGE_RNG_TOOLS=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
@@ -53,6 +53,8 @@ BR2_PACKAGE_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_FIT_CHECK_SIGN=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_MKENVIMAGE=y
|
||||
BR2_PACKAGE_PYTHON3=y
|
||||
BR2_PACKAGE_PYTHON_CRYPTOGRAPHY=y
|
||||
BR2_PACKAGE_PYTHON_GUNICORN=y
|
||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||
BR2_PACKAGE_LIBSSH2=y
|
||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||
@@ -79,6 +81,9 @@ BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||
BR2_PACKAGE_NETSNMP=y
|
||||
BR2_PACKAGE_NFTABLES=y
|
||||
BR2_PACKAGE_NGINX=y
|
||||
BR2_PACKAGE_NGINX_HTTP_SSL_MODULE=y
|
||||
BR2_PACKAGE_NGINX_HTTP_V2_MODULE=y
|
||||
BR2_PACKAGE_NMAP=y
|
||||
BR2_PACKAGE_NMAP_NCAT=y
|
||||
BR2_PACKAGE_NMAP_NMAP=y
|
||||
@@ -91,6 +96,7 @@ BR2_PACKAGE_TRACEROUTE=y
|
||||
BR2_PACKAGE_ULOGD=y
|
||||
BR2_PACKAGE_BASH_COMPLETION=y
|
||||
BR2_PACKAGE_SUDO=y
|
||||
BR2_PACKAGE_TTYD=y
|
||||
BR2_PACKAGE_HTOP=y
|
||||
BR2_PACKAGE_IRQBALANCE=y
|
||||
BR2_PACKAGE_KMOD_TOOLS=y
|
||||
@@ -136,12 +142,14 @@ BR2_PACKAGE_K8S_LOGGER=y
|
||||
BR2_PACKAGE_KEYACK=y
|
||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
BR2_PACKAGE_NETBROWSE=y
|
||||
BR2_PACKAGE_PODMAN=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_BTRFS=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_LIBINPUT=y
|
||||
DISK_IMAGE_BOOT_BIN=y
|
||||
GNS3_APPLIANCE_RAM=512
|
||||
|
||||
+11
-2
@@ -16,6 +16,7 @@ BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/xattrs"
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_SYSTEM_BIN_SH_BASH=y
|
||||
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
BR2_SYSTEM_DHCP="eth0"
|
||||
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA"
|
||||
@@ -27,7 +28,7 @@ BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image
|
||||
BR2_ROOTFS_POST_SCRIPT_ARGS="-c $(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/r2s/genimage.cfg"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.11"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.22"
|
||||
BR2_LINUX_KERNEL_PATCH="$(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/r2s/rk3328-nanopi-r2s-dts.patch"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="$(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/r2s/linux_defconfig"
|
||||
@@ -63,6 +64,8 @@ BR2_PACKAGE_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_FIT_CHECK_SIGN=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_MKENVIMAGE=y
|
||||
BR2_PACKAGE_PYTHON3=y
|
||||
BR2_PACKAGE_PYTHON_CRYPTOGRAPHY=y
|
||||
BR2_PACKAGE_PYTHON_GUNICORN=y
|
||||
BR2_PACKAGE_CA_CERTIFICATES=y
|
||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||
BR2_PACKAGE_LIBSSH2=y
|
||||
@@ -91,6 +94,9 @@ BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||
BR2_PACKAGE_NETSNMP=y
|
||||
BR2_PACKAGE_NFTABLES=y
|
||||
BR2_PACKAGE_NGINX=y
|
||||
BR2_PACKAGE_NGINX_HTTP_SSL_MODULE=y
|
||||
BR2_PACKAGE_NGINX_HTTP_V2_MODULE=y
|
||||
BR2_PACKAGE_NMAP=y
|
||||
BR2_PACKAGE_NMAP_NCAT=y
|
||||
BR2_PACKAGE_NMAP_NMAP=y
|
||||
@@ -103,6 +109,7 @@ BR2_PACKAGE_TRACEROUTE=y
|
||||
BR2_PACKAGE_ULOGD=y
|
||||
BR2_PACKAGE_BASH_COMPLETION=y
|
||||
BR2_PACKAGE_SUDO=y
|
||||
BR2_PACKAGE_TTYD=y
|
||||
BR2_PACKAGE_HTOP=y
|
||||
BR2_PACKAGE_IRQBALANCE=y
|
||||
BR2_PACKAGE_KMOD_TOOLS=y
|
||||
@@ -165,12 +172,14 @@ BR2_PACKAGE_K8S_LOGGER=y
|
||||
BR2_PACKAGE_KEYACK=y
|
||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
BR2_PACKAGE_NETBROWSE=y
|
||||
BR2_PACKAGE_PODMAN=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_BTRFS=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_LIBINPUT=y
|
||||
# SIGN_ENABLED is not set
|
||||
# GNS3_APPLIANCE is not set
|
||||
|
||||
@@ -1,121 +0,0 @@
|
||||
BR2_x86_64=y
|
||||
BR2_x86_corei7=y
|
||||
BR2_TOOLCHAIN_EXTERNAL=y
|
||||
BR2_TOOLCHAIN_EXTERNAL_GDB_SERVER_COPY=y
|
||||
BR2_DL_DIR="${BR2_EXTERNAL_INFIX_PATH}/dl"
|
||||
BR2_CCACHE=y
|
||||
BR2_CCACHE_DIR="${BR2_EXTERNAL_INFIX_PATH}/.ccache"
|
||||
BR2_ENABLE_DEBUG=y
|
||||
BR2_GLOBAL_PATCH_DIR="${BR2_EXTERNAL_INFIX_PATH}/patches"
|
||||
BR2_TARGET_GENERIC_HOSTNAME="infix"
|
||||
BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_MDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
BR2_SYSTEM_DHCP="eth0"
|
||||
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA"
|
||||
BR2_GENERATE_LOCALE="en_US en_CA"
|
||||
BR2_TARGET_TZ_INFO=y
|
||||
BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/classic/rootfs"
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/classic/post-build.sh"
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.11"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
BR2_LINUX_KERNEL_NEEDS_HOST_LIBELF=y
|
||||
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
||||
BR2_PACKAGE_BUSYBOX_SHOW_OTHERS=y
|
||||
BR2_PACKAGE_JQ=y
|
||||
BR2_PACKAGE_RNG_TOOLS=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_FIT_CHECK_SIGN=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_MKENVIMAGE=y
|
||||
BR2_PACKAGE_CA_CERTIFICATES=y
|
||||
BR2_PACKAGE_LIBCURL_CURL=y
|
||||
BR2_PACKAGE_NSS_MDNS=y
|
||||
BR2_PACKAGE_ONIGURUMA=y
|
||||
BR2_PACKAGE_AVAHI=y
|
||||
# BR2_PACKAGE_AVAHI_AUTOIPD is not set
|
||||
BR2_PACKAGE_AVAHI_DAEMON=y
|
||||
BR2_PACKAGE_AVAHI_DEFAULT_SERVICES=y
|
||||
BR2_PACKAGE_DHCPCD=y
|
||||
BR2_PACKAGE_DNSMASQ=y
|
||||
BR2_PACKAGE_DROPBEAR=y
|
||||
BR2_PACKAGE_DROPBEAR_DISABLE_REVERSEDNS=y
|
||||
BR2_PACKAGE_DROPBEAR_WTMP=y
|
||||
BR2_PACKAGE_DROPBEAR_LASTLOG=y
|
||||
BR2_PACKAGE_DROPBEAR_LEGACY_CRYPTO=y
|
||||
BR2_PACKAGE_ETHTOOL=y
|
||||
BR2_PACKAGE_FPING=y
|
||||
# BR2_PACKAGE_IFUPDOWN_SCRIPTS is not set
|
||||
BR2_PACKAGE_IPROUTE2=y
|
||||
BR2_PACKAGE_IPTABLES=y
|
||||
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_LYNX=y
|
||||
BR2_PACKAGE_MTR=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NFTABLES=y
|
||||
BR2_PACKAGE_NMAP=y
|
||||
BR2_PACKAGE_NMAP_NMAP=y
|
||||
BR2_PACKAGE_NMAP_NPING=y
|
||||
BR2_PACKAGE_OPENRESOLV=y
|
||||
BR2_PACKAGE_SOCAT=y
|
||||
BR2_PACKAGE_TCPDUMP=y
|
||||
BR2_PACKAGE_TRACEROUTE=y
|
||||
BR2_PACKAGE_DIALOG=y
|
||||
BR2_PACKAGE_PDMENU=y
|
||||
BR2_PACKAGE_HTOP=y
|
||||
BR2_PACKAGE_IRQBALANCE=y
|
||||
BR2_PACKAGE_KMOD_TOOLS=y
|
||||
BR2_PACKAGE_PWGEN=y
|
||||
BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
BR2_PACKAGE_MG=y
|
||||
BR2_PACKAGE_MOST=y
|
||||
BR2_PACKAGE_NANO=y
|
||||
BR2_TARGET_ROOTFS_SQUASHFS=y
|
||||
# BR2_TARGET_ROOTFS_TAR is not set
|
||||
BR2_TARGET_EDK2=y
|
||||
BR2_TARGET_GRUB2=y
|
||||
BR2_TARGET_GRUB2_X86_64_EFI=y
|
||||
BR2_TARGET_GRUB2_BUILTIN_MODULES_EFI="boot linux ext2 squash4 part_gpt normal efi_gop configfile loadenv test echo reboot net efinet tftp loopback"
|
||||
BR2_TARGET_GRUB2_BUILTIN_CONFIG_EFI="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/grub-embed.cfg"
|
||||
BR2_TARGET_GRUB2_INSTALL_TOOLS=y
|
||||
BR2_PACKAGE_HOST_DOSFSTOOLS=y
|
||||
BR2_PACKAGE_HOST_E2FSPROGS=y
|
||||
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
||||
BR2_PACKAGE_HOST_GENEXT2FS=y
|
||||
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||
BR2_PACKAGE_HOST_MTOOLS=y
|
||||
BR2_PACKAGE_HOST_RAUC=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||
INFIX_VARIANT_CLASSIC=y
|
||||
BR2_PACKAGE_FACTORY=y
|
||||
BR2_PACKAGE_FINIT_SULOGIN=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_MODULES_LOAD=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_MODPROBE=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_RTC=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
||||
BR2_PACKAGE_IFUPDOWN_NG=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
DISK_IMAGE_BOOT_BIN=y
|
||||
@@ -11,20 +11,21 @@ BR2_TARGET_GENERIC_HOSTNAME="infix"
|
||||
BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/xattrs"
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_SYSTEM_BIN_SH_BASH=y
|
||||
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
BR2_SYSTEM_DHCP="eth0"
|
||||
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA"
|
||||
BR2_GENERATE_LOCALE="en_US en_CA"
|
||||
BR2_TARGET_TZ_INFO=y
|
||||
BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/rootfs"
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/post-build.sh"
|
||||
BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/rootfs"
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.11"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.22"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -48,6 +49,8 @@ BR2_PACKAGE_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_FIT_CHECK_SIGN=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_MKENVIMAGE=y
|
||||
BR2_PACKAGE_PYTHON3=y
|
||||
BR2_PACKAGE_PYTHON_CRYPTOGRAPHY=y
|
||||
BR2_PACKAGE_PYTHON_GUNICORN=y
|
||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||
BR2_PACKAGE_LIBSSH2=y
|
||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||
@@ -74,6 +77,9 @@ BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||
BR2_PACKAGE_NETSNMP=y
|
||||
BR2_PACKAGE_NFTABLES=y
|
||||
BR2_PACKAGE_NGINX=y
|
||||
BR2_PACKAGE_NGINX_HTTP_SSL_MODULE=y
|
||||
BR2_PACKAGE_NGINX_HTTP_V2_MODULE=y
|
||||
BR2_PACKAGE_NMAP=y
|
||||
BR2_PACKAGE_NMAP_NCAT=y
|
||||
BR2_PACKAGE_NMAP_NMAP=y
|
||||
@@ -86,6 +92,7 @@ BR2_PACKAGE_TRACEROUTE=y
|
||||
BR2_PACKAGE_ULOGD=y
|
||||
BR2_PACKAGE_BASH_COMPLETION=y
|
||||
BR2_PACKAGE_SUDO=y
|
||||
BR2_PACKAGE_TTYD=y
|
||||
BR2_PACKAGE_HTOP=y
|
||||
BR2_PACKAGE_IRQBALANCE=y
|
||||
BR2_PACKAGE_KMOD_TOOLS=y
|
||||
@@ -139,11 +146,13 @@ BR2_PACKAGE_K8S_LOGGER=y
|
||||
BR2_PACKAGE_KEYACK=y
|
||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
BR2_PACKAGE_NETBROWSE=y
|
||||
BR2_PACKAGE_PODMAN=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_BTRFS=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
GNS3_APPLIANCE_RAM=512
|
||||
GNS3_APPLIANCE_IFNUM=10
|
||||
|
||||
+48
-4
@@ -7,10 +7,20 @@ All notable changes to the project are documented in this file.
|
||||
[v24.03.0][UNRELEASED]
|
||||
-------------------------
|
||||
|
||||
Please note, as of this release the Infix Classic variant has been
|
||||
dropped. This was the legacy, pre-NETCONF, Infix with manual config of
|
||||
the system using a persistent `/etc`. It may be resurrected later as a
|
||||
separate project. Going forward Infix' focus is entirely on NETCONF.
|
||||
|
||||
> Development in progress, for daily updates see the team board:
|
||||
> <https://github.com/orgs/kernelkit/projects/3/views/2>
|
||||
|
||||
### Changes
|
||||
- Bump the base Linux kernel version to 6.6
|
||||
- Drop Classic variant to reduce overhead, simplify build & release
|
||||
processes, and focus on NETCONF for Arm64 and Amd64 platforms
|
||||
- Add hostname restrictions to ietf-system, and infix-dhcp-client
|
||||
models. Max 64 characters on Linux systems
|
||||
- The bridge model now has built-in validation of port memberships,
|
||||
i.e., a port must be a bridge member to be used in VLAN filtering
|
||||
- The bridge model only permits the bridge itself to be a tagged
|
||||
@@ -18,9 +28,30 @@ All notable changes to the project are documented in this file.
|
||||
such bridges is to use a VLAN interface on top
|
||||
- A VLAN filtering bridge now validates that no IP address has been
|
||||
set. Use a VLAN interface on top for that (see above)
|
||||
- Container documentation: CLI prompts have been updated to match the
|
||||
examples used in other parts of the User Guide
|
||||
- Issue #358: translate YANG model's LOWER-LAYER-DOWN -> LINK-DOWN in
|
||||
CLI `show interfaces` command
|
||||
- Issue #360: document factory-config, startup-config, and the various
|
||||
failure modes in the system
|
||||
- Issue #361: document how a privileged container can break out of its
|
||||
confinement and run host commands, e.g., call `sysrepocfg`
|
||||
- Issue #365: add limited support for container capabilities, e.g., to
|
||||
enable `CAP_NET_RAW` to allow containers to use `ping`. This allows
|
||||
users to avoid enabling privileged mode
|
||||
- Issue #367: setting date/time over NETCONF now saves system time also
|
||||
to the RTC, which otherwise is only saved on reboot or power-down
|
||||
- Add support for static multicast filters, MAC, IPv4 and IPv6 groups
|
||||
are supported.
|
||||
- Include Buildroot `legal-info` in releases, i.e., licenses, sources
|
||||
with patches, as well as csv files for packages and toolchain
|
||||
- Issue #369: Remove limitation that the routing instance must be
|
||||
named 'default'
|
||||
|
||||
### Fixes
|
||||
|
||||
- Issue #391 Creating VLAN interface in the CLI with "edit interface vlanN"
|
||||
does not set VLAN id to N.
|
||||
- confd: Fix memory leak when operating on candidate configuration.
|
||||
- CLI: fix VLAN inference for interfaces named `eth0.1`, i.e., VID 1 on
|
||||
lower-layer-if `eth0`. Only affects automatic inference in the CLI,
|
||||
entering the values manually (CLI/NETCONF) not affected by this bug
|
||||
@@ -32,6 +63,19 @@ All notable changes to the project are documented in this file.
|
||||
- Fix #328: when setting up a VLAN filtering bridge, the PVID for bridge
|
||||
ports defaulted to 1, making it impossible to set up "tagged-only"
|
||||
ports which drop ingressing untagged traffic
|
||||
- Fix #358: MAC address no longer shown for bridge interfaces in CLI
|
||||
`show interfaces` command
|
||||
- Fix #366: static routes from container host interfaces do not work.
|
||||
Documentation updated with an example
|
||||
- Fix #368: upgrading `oci-archive:/` images fail because system thinks
|
||||
the image can be pulled from a localhost registry. Documentation has
|
||||
also been updated, describing various methods and how to upgrade them
|
||||
- Fix #370: despite the documentation stating containers must explicitly
|
||||
declare `network` settings, Infix v23.02 had a late regression that
|
||||
reverted back to the podman default: network behind a CNI bridge
|
||||
(firewalled and NAT:ed, hidden from the rest of the network)
|
||||
- Fix #385: segfault in helper function when disabling the DHCP client
|
||||
using `no dhcp-client` from the CLI
|
||||
|
||||
|
||||
[v24.02.0][] - 2024-03-01
|
||||
@@ -468,11 +512,11 @@ Currently supported models:
|
||||
- Replace `ietf-if-vlan-encapsulation` YANG model with the native
|
||||
`infix-if-vlan` model. This fits better with Linux VLAN interfaces and
|
||||
simplifies the syntax greatly. For details, see PR #179
|
||||
|
||||
|
||||
admin@example:/config/interfaces/interface/eth0.10/> set vlan id 10 lower-layer-if eth0
|
||||
|
||||
- The following new NETCONF interface operational counters have been added:
|
||||
|
||||
|
||||
| **YANG** | **Linux / Ethtool** |
|
||||
|-----------------------------|-----------------------------------|
|
||||
| `out-frames` | `FramesTransmittedOK` |
|
||||
@@ -510,7 +554,7 @@ Currently supported models:
|
||||
|
||||
- Fix #106: confd: drop deviation `ietf-system:timezone-utc-offset`
|
||||
- Fix #151: Operational status broken in v23.09
|
||||
- Fix #159: Hacky generation of `/etc/resolv.conf` at boot
|
||||
- Fix #159: Hacky generation of `/etc/resolv.conf` at boot
|
||||
- Fix #162: VLAN interface without encapsulation is accepted by YANG model
|
||||
|
||||
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
variant.md
|
||||
@@ -0,0 +1,35 @@
|
||||
|
||||
Welcome to Infix, your friendly Network Operating System! On these
|
||||
pages you can find both user and developer documentation.
|
||||
|
||||
> Topics on configuring the system include CLI examples, every setting
|
||||
> is also possible to perform using NETCONF. In fact, the Infix test
|
||||
> system solely relies on NETCONF for configuring network topologies.
|
||||
|
||||
The CLI documentation is also available from inside the CLI itself using
|
||||
the `help` command.
|
||||
|
||||
- **CLI Topics**
|
||||
- [Introduction to the CLI](cli/introduction.md)
|
||||
- [CLI User's Guide](cli/tutorial.md)
|
||||
- [Quick Overview](cli/quick.md)
|
||||
- **Infix User Guide**
|
||||
- [Introduction](introduction.md)
|
||||
- [System Configuration](system.md)
|
||||
- [Network Configuration](networking.md)
|
||||
- **Infix In-Depth**
|
||||
- [Boot Procedure](boot.md)
|
||||
- [Branding & Releases](branding.md)
|
||||
- [Containers in Infix](container.md)
|
||||
- [Find Your Device on the Network](discovery.md)
|
||||
- [Hardware Info & Status](hardware.md)
|
||||
- [Scripting Infix](scripting.md)
|
||||
- [Virtual Environments](virtual.md)
|
||||
- [Vital Product Data (VPD)](vpd.md)
|
||||
- [YANG to Ethtool Mapping](eth-counters.md)
|
||||
- [Origin & Licensing](license.md)
|
||||
- **Developer Topics**
|
||||
- [Developer's Guide](developers-guide.md)
|
||||
- [Developing with Infix](override-package.md)
|
||||
- [Regression Testing with Infamy](testing.md)
|
||||
|
||||
@@ -331,8 +331,6 @@ rollbacks when upgrading to a new version.
|
||||
|
||||
Non-volatile storage of the system configuration and user data.
|
||||
Concretely, user data is everything stored under `/root` and `/home`.
|
||||
Depending on the operating mode, the configuration is either the NETCONF
|
||||
databases from `/cfg`, or the contents of `/etc` in classic mode.
|
||||
|
||||
|
||||
### `var` - Variable Data
|
||||
|
||||
@@ -12,17 +12,18 @@ short guide intends to help you with that.
|
||||
## Key Concepts
|
||||
|
||||
The two modes in the CLI are the admin-exec and the configure context.
|
||||
When logging in to the system, be it from console or SSH, you land in
|
||||
admin-exec. Here you can inspect the system status and do operations
|
||||
to debug networking issues, e.g. ping. You can also enter configure
|
||||
context by typing: `configure`
|
||||
|
||||
When logging in to the system, be it from console or SSH, you first have
|
||||
a stopover in a UNIX shell, usually Bash. Type `cli` to enter the CLI
|
||||
and finally land in admin-exec. Here you can inspect system status and
|
||||
do operations to debug networking issues, e.g. ping. You can also enter
|
||||
configure context by typing: `configure`
|
||||
|
||||
The system has several datastores (or files):
|
||||
|
||||
- `factory-config` consists of a set of default configurations, some
|
||||
static and others generated per-device, e.g., a unique hostname and
|
||||
number of ports/interfaces. This file is generated at boot, if it
|
||||
does not exist, i.e., only on first boot or after factory reset.
|
||||
number of ports/interfaces. This file is generated at boot.
|
||||
- `startup-config` is created from `factory-config` at boot if it does
|
||||
not exist. It is loaded as the system configuration on each boot.
|
||||
- `running-config` is what is actively running on the system. If no
|
||||
|
||||
@@ -66,5 +66,5 @@ admin@host:/config/system/> set text-editor <TAB>
|
||||
emacs nano vi
|
||||
admin@host:/config/system/> set text-editor nano
|
||||
admin@host:/config/system/> leave
|
||||
admin@example:/>
|
||||
admin@host:/>
|
||||
```
|
||||
|
||||
+343
-113
@@ -5,6 +5,8 @@ Containers in Infix
|
||||
* [Caution](#caution)
|
||||
* [Getting Started](#getting-started)
|
||||
* [Examples](#examples)
|
||||
* [Container Images](#container-images)
|
||||
* [Upgrading a Container Image](#upgrading-a-container-image)
|
||||
* [Networking and Containers](#networking-and-containers)
|
||||
* [Container Bridge](#container-bridge)
|
||||
* [Container Host Interface](#container-host-interface)
|
||||
@@ -13,10 +15,10 @@ Containers in Infix
|
||||
* [Content Mounts](#content-mounts)
|
||||
* [Example Containers](#example-containers)
|
||||
* [System Container](#system-container)
|
||||
* [Application Container: nftables](#application-container--nftables)
|
||||
* [Application Container: ntpd](#application-container--ntpd)
|
||||
* [Upgrading a Container Image](#upgradeing-a-container-image)
|
||||
|
||||
* [Application Container: nftables](#application-container-nftables)
|
||||
* [Application Container: ntpd](#application-container-ntpd)
|
||||
* [Advanced](#advanced)
|
||||
* [Running Host Commands From Container](#running-host-commands-from-container)
|
||||
|
||||
Introduction
|
||||
------------
|
||||
@@ -42,20 +44,24 @@ container networking in podman.
|
||||
Caution
|
||||
-------
|
||||
|
||||
A word of warning, containers can run on your system in privileged mode,
|
||||
as `root`. This gives them full access to devices on your system. But
|
||||
even when though unprivileged containers are fenced from the host with
|
||||
Linux namespaces, and resource limited using Linux cgroups, which scope
|
||||
container applications from seeing and accessing the complete system,
|
||||
there is no guarantee that an application cannot ever break out of this
|
||||
confinement.
|
||||
A word of warning. Containers can run on your system in privileged
|
||||
mode, as `root`, giving them full access to devices on your system.
|
||||
Even though containers are fenced from the host with Linux namespaces,
|
||||
resource limited using cgroups, and normally run with capped privileges,
|
||||
a privileged container is relatively easy to break out of. A trivial
|
||||
example is given in the [Advanced](#advanced) section of this document.
|
||||
|
||||
We recommend avoiding privileged containers, if possible (they do have
|
||||
valid use-cases) and instead use [capabilities](#capabilities).
|
||||
|
||||
Remember:
|
||||
|
||||
- If the system is compromised, containers can be used to easily
|
||||
install malicious software in your system and over the network
|
||||
- Your system is as secure as anything you run in the container
|
||||
- If you run containers, there is no security guarantee of any kind
|
||||
- Running 3rd party container images on your system could open a
|
||||
security hole/attack vector/attack surface
|
||||
security hole/attack vector/surface
|
||||
- An expert with knowledge how to build exploits will be able to
|
||||
jailbreak/elevate to root even if best practices are followed
|
||||
|
||||
@@ -101,28 +107,187 @@ application to run.
|
||||
|
||||
Classic Hello World:
|
||||
|
||||
admin@example-c0-ff-ee:/> container run docker://hello-world
|
||||
admin@example:/> container run docker://hello-world
|
||||
|
||||
Persistent web server using nginx, sharing the host's network:
|
||||
|
||||
admin@example-c0-ff-ee:/> configure
|
||||
admin@example-c0-ff-ee:/config> edit container web
|
||||
admin@example-c0-ff-ee:/config/container/web> set image docker://nginx:alpine
|
||||
admin@example-c0-ff-ee:/config/container/web> set publish 80:80
|
||||
admin@example-c0-ff-ee:/config/container/web> set network host
|
||||
admin@example-c0-ff-ee:/config/container/web> leave
|
||||
admin@example-c0-ff-ee:/> show container
|
||||
admin@example:/> configure
|
||||
admin@example:/config> edit container web
|
||||
admin@example:/config/container/web> set image docker://nginx:alpine
|
||||
admin@example:/config/container/web> set publish 80:80
|
||||
admin@example:/config/container/web> set network host
|
||||
admin@example:/config/container/web> leave
|
||||
admin@example:/> show container
|
||||
|
||||
Exit to the shell and verify the service with curl, or try to attach
|
||||
to your device's IP address using your browser:
|
||||
|
||||
admin@example-c0-ff-ee:~$ curl http://localhost
|
||||
admin@example:~$ curl http://localhost
|
||||
|
||||
or connect to port 80 of your running Infix system with a browser. See
|
||||
the following sections for how to add more interfaces and manage your
|
||||
container at runtime.
|
||||
|
||||
|
||||
Container Images
|
||||
----------------
|
||||
|
||||
The underlying `podman` project support importing and fetching images in
|
||||
a variety of ways, the most common ones are also supported by Infix. In
|
||||
this section we present how to use them and in the next section we show
|
||||
how to upgrade to a newer base image.
|
||||
|
||||
The CLI help shows:
|
||||
|
||||
admin@example:/config/container/system/> help image
|
||||
NAME
|
||||
image <string>
|
||||
|
||||
DESCRIPTION
|
||||
Docker image for the container: [transport]name[:tag|@digest]
|
||||
|
||||
quay.io/username/myimage -- Pull myimage:latest
|
||||
docker://busybox -- Pull busybox:latest from Docker Hub
|
||||
docker://ghcr.io/usr/img -- Pull img:latest from GitHub packages
|
||||
dir:/media/usb/myimage:1.1 -- Use myimage v1.1 from USB media
|
||||
docker-archive:/tmp/archive -- Use archive:latest from tarball
|
||||
oci-archive:/lib/oci/archive -- Use archive:latest from OCI archive
|
||||
May be in .tar or .tar.gz format
|
||||
|
||||
Note: if a remote repository cannot be reached, the creation of the
|
||||
container will be put on a queue that retries pull every time
|
||||
there is a route change in the host's system.
|
||||
|
||||
> **Note::** the built-in help system in the CLI is generated from the
|
||||
> YANG model, so the same information is also available for remote
|
||||
> NETCONF users.
|
||||
|
||||
The two most common variants are `docker://` and `oci-archive:/`.
|
||||
|
||||
The former requires a working Docker registry and the latter operates on
|
||||
a plain OCI archive. Infix does not come with a built-in registry, so
|
||||
the `docker://` option is best used with external services, which in
|
||||
turn require [networking][0] to be up. In a deployment phase the
|
||||
easiest may be to set up a single interface on your host system with
|
||||
DHCP client.
|
||||
|
||||
The default method is `docker://`, so when setting the `image` for your
|
||||
container, you can omit the `docker://` prefix. You can also use the
|
||||
admin-exec command `container pull docker://...`, and when configuring a
|
||||
container `podman` will check first if it has the image before trying to
|
||||
download anything. (See also the upgrade section, below.)
|
||||
|
||||
The `oci-archive:/` is interesting since many users may not have, or do
|
||||
not want to, publish their images in a registry. Use the Docker [OCI
|
||||
exporter][5] or any other tool that supports generating [OCI Image][3]
|
||||
format. Infix supports loading both `.tar` or `.tar.gz` formats.
|
||||
|
||||
Here we show a simple example of fetching an OCI image to the system,
|
||||
but many others exist, tools like `wget`, `curl`, and `scp` come to
|
||||
mind.
|
||||
|
||||
**Shell OCI Example:**
|
||||
|
||||
admin@example:~$ cd /var/tmp/
|
||||
admin@example:/var/tmp$ sudo wget https://github.com/kernelkit/curiOS/releases/download/edge/curios-oci-amd64.tar.gz
|
||||
Connecting to github.com (140.82.121.3:443)
|
||||
wget: note: TLS certificate validation not implemented
|
||||
Connecting to objects.githubusercontent.com (185.199.109.133:443)
|
||||
saving to 'curios-oci-amd64.tar.gz'
|
||||
curios-oci-amd64.tar 100% |*********************************| 7091k 0:00:00 ETA
|
||||
'curios-oci-amd64.tar.gz' saved
|
||||
admin@example:/var/tmp$ ll
|
||||
total 7104
|
||||
drwxr-xr-x 3 root root 4096 Mar 27 14:22 ./
|
||||
drwxr-xr-x 14 root root 4096 Mar 27 11:57 ../
|
||||
-rw-r--r-- 1 root root 7261785 Mar 27 14:22 curios-oci-amd64.tar.gz
|
||||
drwx------ 6 frr frr 4096 Mar 27 11:57 frr/
|
||||
|
||||
Importing the image into podman can be done either from the CLI
|
||||
admin-exec context ...
|
||||
|
||||
admin@example:/var/tmp$ cli
|
||||
admin@example:/> container load /var/tmp/curios-oci-amd64.tar.gz name curios:edge
|
||||
|
||||
> By assigning The `name curios:edge` is the tag you give the imported
|
||||
> (raw) archive which you can then reference in your container image
|
||||
> configuration: `set image curios:edge`.
|
||||
|
||||
... or by giving the container configuration the full path to the OCI
|
||||
archive, which helps greatly with container upgrades (see below):
|
||||
|
||||
admin@example:/config/container/system/> set image oci-archive:/var/tmp/curios-oci-amd64.tar.gz
|
||||
|
||||
|
||||
Upgrading a Container Image
|
||||
---------------------------
|
||||
|
||||
> **Note:** the default writable layer is lost when upgrading the image
|
||||
> Use named volumes for directories with writable content you wish to
|
||||
> keep over an upgrade.
|
||||
|
||||
All container configurations are locked to the image hash at the time of
|
||||
first download, not just ones that use an `:edge` or `:latest` tag. An
|
||||
upgrade of containers using versioned images is more obvious -- update
|
||||
the configuration to use the new `image:tag` -- the latter is a bit
|
||||
trickier. Either remove the configuration and recreate it (leave/apply
|
||||
the changes between), or use the admin-exec level command:
|
||||
|
||||
admin@example:/> container upgrade NAME
|
||||
|
||||
Where `NAME` is the name of your container. This command stops the
|
||||
container, does `container pull IMAGE`, and then recreates it with the
|
||||
new image. Upgraded containers are automatically restarted.
|
||||
|
||||
**Example using registry:**
|
||||
|
||||
admin@example:/> container upgrade system
|
||||
system
|
||||
Trying to pull ghcr.io/kernelkit/curios:edge...
|
||||
Getting image source signatures
|
||||
Copying blob 07bfba95fe93 done
|
||||
Copying config 0cb6059c0f done
|
||||
Writing manifest to image destination
|
||||
Storing signatures
|
||||
0cb6059c0f4111650ddbc7dbc4880c64ab8180d4bdbb7269c08034defc348f17
|
||||
system: not running.
|
||||
59618cc3c84bef341c1f5251a62be1592e459cc990f0b8864bc0f5be70e60719
|
||||
|
||||
An OCI archive image can be upgraded in a similar manner, the first step
|
||||
is of course to get the new archive onto the system (see above), and
|
||||
then, provided the `oci-archive:/path/to/archive` format is used, call
|
||||
the upgrade command as
|
||||
|
||||
admin@example:/> container upgrade system
|
||||
Upgrading container system with local archive: oci-archive:/var/tmp/curios-oci-amd64.tar.gz ...
|
||||
7ab4a07ee0c6039837419b7afda4da1527a70f0c60c0f0ac21cafee05ba24b52
|
||||
|
||||
|
||||
Capabilities
|
||||
-------------
|
||||
|
||||
An unprivileged container works for almost all use-cases, but there are
|
||||
occasions where they are too restricted and users being looking for the
|
||||
`privileged` flag. Capabilities offers a middle ground.
|
||||
|
||||
For example, a system container from which `ping` does not work:
|
||||
|
||||
admin@example:/config/container/system/> edit capabilities
|
||||
admin@example:/config/container/system/capabilities/> set add net_raw
|
||||
admin@example:/config/container/system/capabilities/> end
|
||||
admin@infix-00-00-00:/config/container/system/> show
|
||||
...
|
||||
capabilities {
|
||||
add net_raw;
|
||||
}
|
||||
...
|
||||
|
||||
Infix supports a subset of all [capabilities][6] that are relevant for
|
||||
containers. Please note, that this is and advanced topic and will
|
||||
require time and analysis of your container application to figure out
|
||||
which capabilities you need.
|
||||
|
||||
|
||||
Networking and Containers
|
||||
-------------------------
|
||||
|
||||
@@ -146,10 +311,10 @@ what makes container use seem to be so simple.
|
||||
|
||||
All interface configuration is done in configure context.
|
||||
|
||||
admin@example-c0-ff-ee:/> configure
|
||||
admin@example-c0-ff-ee:/config> edit interface docker0
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/> set container-network
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/> leave
|
||||
admin@example:/> configure
|
||||
admin@example:/config> edit interface docker0
|
||||
admin@example:/config/interface/docker0/> set container-network
|
||||
admin@example:/config/interface/docker0/> leave
|
||||
|
||||
There is more to this story. When using the CLI, and sticking to common
|
||||
interface nomenclature, Infix helps you with some of the boring stuff.
|
||||
@@ -157,8 +322,8 @@ E.g., creating a new interface with a name like `brN` or `dockerN`
|
||||
automatically *infers* the interface types, which you would otherwise
|
||||
have to set manually:
|
||||
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/> set type bridge
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/> set container-network type bridge
|
||||
admin@example:/config/interface/docker0/> set type bridge
|
||||
admin@example:/config/interface/docker0/> set container-network type bridge
|
||||
|
||||
> **Note:** when doing the same operation over NETCONF there is no
|
||||
> inference, so all the "magic" settings needs to be defined. This
|
||||
@@ -182,16 +347,16 @@ other networking parameters (DNS, default route) are set up.
|
||||
Some of the defaults of a container `bridge` can be changed, e.g.,
|
||||
instead of `set container-network type bridge`, above, do:
|
||||
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/> edit container-network
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/container-network/> set type bridge
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/container-network/> edit subnet 192.168.0.0/16
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/container-network/subnet/192.168.0.0/16/> set gateway 192.168.255.254
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/container-network/subnet/192.168.0.0/16/> end
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/container-network/> edit route 10.0.10.0/24
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/container-network/route/10.0.10.0/24/> set gateway 192.168.10.254
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/container-network/route/10.0.10.0/24/> end
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/container-network/> end
|
||||
admin@example-c0-ff-ee:/config/interface/docker0/> leave
|
||||
admin@example:/config/interface/docker0/> edit container-network
|
||||
admin@example:/config/interface/docker0/container-network/> set type bridge
|
||||
admin@example:/config/interface/docker0/container-network/> edit subnet 192.168.0.0/16
|
||||
admin@example:/config/interface/docker0/container-network/subnet/192.168.0.0/16/> set gateway 192.168.255.254
|
||||
admin@example:/config/interface/docker0/container-network/subnet/192.168.0.0/16/> end
|
||||
admin@example:/config/interface/docker0/container-network/> edit route 10.0.10.0/24
|
||||
admin@example:/config/interface/docker0/container-network/route/10.0.10.0/24/> set gateway 192.168.10.254
|
||||
admin@example:/config/interface/docker0/container-network/route/10.0.10.0/24/> end
|
||||
admin@example:/config/interface/docker0/container-network/> end
|
||||
admin@example:/config/interface/docker0/> leave
|
||||
|
||||
Other network settings, like DNS and domain, use built-in defaults, but
|
||||
can be overridden from each container. Other common settings per
|
||||
@@ -203,11 +368,11 @@ in a `bridge`. Below an example of a system container calls `set
|
||||
network interface docker0`, here we show how to set options for that
|
||||
network:
|
||||
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/> edit network docker0
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/network/docker0/>
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/network/docker0/> set option
|
||||
admin@example:/config/container/ntpd/> edit network docker0
|
||||
admin@example:/config/container/ntpd/network/docker0/>
|
||||
admin@example:/config/container/ntpd/network/docker0/> set option
|
||||
<string> Options for masquerading container bridges.
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/network/docker0/> help option
|
||||
admin@example:/config/container/ntpd/network/docker0/> help option
|
||||
NAME
|
||||
option <string>
|
||||
|
||||
@@ -218,9 +383,9 @@ network:
|
||||
mac=00:01:02:c0:ff:ee -- set fixed MAC address in container
|
||||
interface_name=foo0 -- set interface name inside container
|
||||
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/network/docker0/> set option ip=172.17.0.2
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/network/docker0/> set option interface_name=wan
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/network/docker0/> leave
|
||||
admin@example:/config/container/ntpd/network/docker0/> set option ip=172.17.0.2
|
||||
admin@example:/config/container/ntpd/network/docker0/> set option interface_name=wan
|
||||
admin@example:/config/container/ntpd/network/docker0/> leave
|
||||
|
||||
|
||||
### Container Host Interface
|
||||
@@ -232,13 +397,13 @@ This works with regular Ethernet interfaces as well, but here we will
|
||||
use a VETH pair as an example along with a regular bridge (where other
|
||||
Ethernet interfaces may live as well).
|
||||
|
||||
admin@example-c0-ff-ee:/config/> edit interface veth0
|
||||
admin@example-c0-ff-ee:/config/interface/veth0/> set veth peer ntpd
|
||||
admin@example-c0-ff-ee:/config/interface/veth0/> set ipv4 address 192.168.0.1 prefix-length 24
|
||||
admin@example-c0-ff-ee:/config/interface/veth0/> end
|
||||
admin@example-c0-ff-ee:/config/> edit interface ntpd
|
||||
admin@example-c0-ff-ee:/config/interface/ntpd/> set ipv4 address 192.168.0.2 prefix-length 24
|
||||
admin@example-c0-ff-ee:/config/interface/ntpd/> set container-network
|
||||
admin@example:/config/> edit interface veth0
|
||||
admin@example:/config/interface/veth0/> set veth peer ntpd
|
||||
admin@example:/config/interface/veth0/> set ipv4 address 192.168.0.1 prefix-length 24
|
||||
admin@example:/config/interface/veth0/> end
|
||||
admin@example:/config/> edit interface ntpd
|
||||
admin@example:/config/interface/ntpd/> set ipv4 address 192.168.0.2 prefix-length 24
|
||||
admin@example:/config/interface/ntpd/> set container-network
|
||||
|
||||
This is a routed setup, where we reserve 192.168.0.0/24 for the network
|
||||
between the host and the `ntpd` container. A perhaps more common case
|
||||
@@ -247,6 +412,35 @@ point of the routed case is that port forwarding from the container in
|
||||
this case is limited to a single interface, not *all interfaces* as is
|
||||
the default in the masquerading container bridge setup.
|
||||
|
||||
When a container has multiple host interfaces it can often be useful to
|
||||
have a default route installed. This can be added from the host with a
|
||||
`0.0.0.0/0` route on one of the interfaces. The following is an example
|
||||
when adding a second VETH pair to the container:
|
||||
|
||||
admin@example:/config/> edit interface veth1a
|
||||
admin@example:/config/interface/veth1a/> set veth peer veth1b
|
||||
admin@example:/config/interface/veth1a/> set ipv4 address 192.168.1.2 prefix-length 24
|
||||
admin@example:/config/interface/veth1a/> set container-network route 0.0.0.0/0 gateway 192.168.1.1
|
||||
admin@example:/config/interface/veth1a/> show
|
||||
type veth;
|
||||
container-network {
|
||||
type host;
|
||||
route 0.0.0.0/0 {
|
||||
gateway 192.168.1.1;
|
||||
}
|
||||
}
|
||||
veth {
|
||||
peer veth1b;
|
||||
}
|
||||
admin@example:/config/interface/veth1a/> end
|
||||
admin@example:/config/> set interface veth1b bridge-port bridge br0
|
||||
|
||||
Please note, container network routes require the base interface also
|
||||
have a static IP address set. Setting only the route, but no address,
|
||||
means the route is skipped.
|
||||
|
||||
> The LAN bridge (br0) in this example has IP address 192.168.1.1.
|
||||
|
||||
|
||||
### Host Networking
|
||||
|
||||
@@ -267,16 +461,16 @@ It is possible to mount files, directories, and even files matching a
|
||||
glob, into a container. This gives precise control over the container's
|
||||
file system:
|
||||
|
||||
admin@example-c0-ff-ee:/config/container/system/> edit mount leds
|
||||
admin@example-c0-ff-ee:/config/container/system/mount/leds> set source /sys/class/leds
|
||||
admin@example-c0-ff-ee:/config/container/system/mount/leds> set target /sys/class/leds
|
||||
admin@example-c0-ff-ee:/config/container/system/mount/leds> end
|
||||
admin@example-c0-ff-ee:/config/container/system/>
|
||||
admin@example:/config/container/system/> edit mount leds
|
||||
admin@example:/config/container/system/mount/leds> set source /sys/class/leds
|
||||
admin@example:/config/container/system/mount/leds> set target /sys/class/leds
|
||||
admin@example:/config/container/system/mount/leds> end
|
||||
admin@example:/config/container/system/>
|
||||
|
||||
Sometimes *volumes* are a better fit. A volume is an automatically
|
||||
created read-writable entity that follows the life of your container.
|
||||
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/> set volume varlib target /var/lib
|
||||
admin@example:/config/container/ntpd/> set volume varlib target /var/lib
|
||||
|
||||
Volumes survive reboots and upgrading of the base image, unlike the
|
||||
persistent writable layer you get by default, which does not survive
|
||||
@@ -297,12 +491,12 @@ very useful when deploying similar systems at multiple sites. When the
|
||||
host loads its `startup-config` (or even `factory-config`) a temporary
|
||||
file is created using the decoded base64 data from the `content` node.
|
||||
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/> edit mount ntpd.conf
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/mount/ntpd.conf> text-editor content
|
||||
admin@example:/config/container/ntpd/> edit mount ntpd.conf
|
||||
admin@example:/config/container/ntpd/mount/ntpd.conf> text-editor content
|
||||
... interactive editor starts up ...
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/mount/ntpd.conf> set target /etc/ntpd.conf
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/mount/ntpd.conf> end
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/>
|
||||
admin@example:/config/container/ntpd/mount/ntpd.conf> set target /etc/ntpd.conf
|
||||
admin@example:/config/container/ntpd/mount/ntpd.conf> end
|
||||
admin@example:/config/container/ntpd/>
|
||||
|
||||
The editor is a small [Emacs clone called Mg][2], see the built-in help
|
||||
text, or press Ctrl-x Ctrl-c to exit and save. When the editor exits
|
||||
@@ -325,12 +519,12 @@ Let's try out what we've learned by setting up a system container, a
|
||||
container providing multiple services, using the `docker0` interface
|
||||
we created previously:
|
||||
|
||||
admin@example-c0-ff-ee:/> configure
|
||||
admin@example-c0-ff-ee:/config> edit container system
|
||||
admin@example-c0-ff-ee:/config/container/system/> set image ghcr.io/kernelkit/curios:edge
|
||||
admin@example-c0-ff-ee:/config/container/system/> set network interface docker0
|
||||
admin@example-c0-ff-ee:/config/container/system/> set publish 222:22
|
||||
admin@example-c0-ff-ee:/config/container/system/> leave
|
||||
admin@example:/> configure
|
||||
admin@example:/config> edit container system
|
||||
admin@example:/config/container/system/> set image ghcr.io/kernelkit/curios:edge
|
||||
admin@example:/config/container/system/> set network interface docker0
|
||||
admin@example:/config/container/system/> set publish 222:22
|
||||
admin@example:/config/container/system/> leave
|
||||
|
||||
> **Note:** ensure you have a network connection to the registry.
|
||||
> If the image cannot be pulled, creation of the container will be
|
||||
@@ -344,25 +538,25 @@ container configuration context for the full syntax.)
|
||||
|
||||
Available containers can be accessed from admin-exec:
|
||||
|
||||
admin@example-c0-ff-ee:/> show container
|
||||
admin@example:/> show container
|
||||
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
|
||||
439af2917b44 ghcr.io/kernelkit/curios:edge 41 hours ago Up 16 hours 0.0.0.0:222->222/tcp system
|
||||
|
||||
This is a system container, so you can "attach" to it by starting a
|
||||
shell (or logging in with SSH):
|
||||
|
||||
admin@example-c0-ff-ee:/> container shell system
|
||||
admin@example:/> container shell system
|
||||
root@439af2917b44:/#
|
||||
|
||||
Notice how the hostname inside the container changes. By default the
|
||||
container ID (hash) is used, but this can be easily changed:
|
||||
|
||||
root@439af2917b44:/# exit
|
||||
admin@infix-00-00-00:/> configure
|
||||
admin@infix-00-00-00:/config/> edit container system
|
||||
admin@infix-00-00-00:/config/container/system/> set hostname sys101
|
||||
admin@infix-00-00-00:/config/container/system/> leave
|
||||
admin@infix-00-00-00:/> container shell system
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit container system
|
||||
admin@example:/config/container/system/> set hostname sys101
|
||||
admin@example:/config/container/system/> leave
|
||||
admin@example:/> container shell system
|
||||
root@sys101:/#
|
||||
|
||||
[^1]: this does not apply to the admin-exec command `container run`.
|
||||
@@ -377,16 +571,16 @@ Infix currently does not have a native firewall configuration, and even
|
||||
when it does it will never expose the full capabilities of `nftables`.
|
||||
For advanced setups, the following is an interesting alternative.
|
||||
|
||||
admin@example-c0-ff-ee:/> configure
|
||||
admin@example-c0-ff-ee:/config> edit container nftables
|
||||
admin@example-c0-ff-ee:/config/container/nftables/> set image ghcr.io/kernelkit/curios-nftables:edge
|
||||
admin@example-c0-ff-ee:/config/container/nftables/> set network host
|
||||
admin@example-c0-ff-ee:/config/container/nftables/> set privileged true
|
||||
admin@example-c0-ff-ee:/config/container/nftables/> edit mount nftables.conf
|
||||
admin@example-c0-ff-ee:/config/container/nftables/mount/nftables.conf/> set target /etc/nftables.conf
|
||||
admin@example-c0-ff-ee:/config/container/nftables/mount/nftables.conf/> text-editor content
|
||||
admin@example:/> configure
|
||||
admin@example:/config> edit container nftables
|
||||
admin@example:/config/container/nftables/> set image ghcr.io/kernelkit/curios-nftables:edge
|
||||
admin@example:/config/container/nftables/> set network host
|
||||
admin@example:/config/container/nftables/> set privileged
|
||||
admin@example:/config/container/nftables/> edit mount nftables.conf
|
||||
admin@example:/config/container/nftables/mount/nftables.conf/> set target /etc/nftables.conf
|
||||
admin@example:/config/container/nftables/mount/nftables.conf/> text-editor content
|
||||
... interactive editor starts up where you can paste your rules ...
|
||||
admin@example-c0-ff-ee:/config/container/nftables/mount/nftables.conf/> leave
|
||||
admin@example:/config/container/nftables/mount/nftables.conf/> leave
|
||||
|
||||
Notice how we `set network host`, so the container can see and act on
|
||||
all the host's interfaces, and that we also have to run the container
|
||||
@@ -404,50 +598,86 @@ file system and store in the host's `startup-config`. However, `ntpd`
|
||||
also saves clock drift information in `/var/lib/ntpd`, so we will also
|
||||
use volumes in this example.
|
||||
|
||||
admin@example-c0-ff-ee:/> configure
|
||||
admin@example-c0-ff-ee:/config> edit container ntpd
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/> set image ghcr.io/kernelkit/curios-ntpd:edge
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/> set network interface ntpd # From veth0 above
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/> edit mount ntp.conf
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/mount/ntp.conf/> set target /etc/ntp.conf
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/mount/ntp.conf/> text-editor content
|
||||
admin@example:/> configure
|
||||
admin@example:/config> edit container ntpd
|
||||
admin@example:/config/container/ntpd/> set image ghcr.io/kernelkit/curios-ntpd:edge
|
||||
admin@example:/config/container/ntpd/> set network interface ntpd # From veth0 above
|
||||
admin@example:/config/container/ntpd/> edit mount ntp.conf
|
||||
admin@example:/config/container/ntpd/mount/ntp.conf/> set target /etc/ntp.conf
|
||||
admin@example:/config/container/ntpd/mount/ntp.conf/> text-editor content
|
||||
... interactive editor starts up where you can paste your rules ...
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/mount/ntp.conf/> end
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/> edit volume varlib
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/volume/varlib/> set target /var/lib
|
||||
admin@example-c0-ff-ee:/config/container/ntpd/volume/varlib/> leave
|
||||
admin@example-c0-ff-ee:/> copy running-config startup-config
|
||||
admin@example:/config/container/ntpd/mount/ntp.conf/> end
|
||||
admin@example:/config/container/ntpd/> edit volume varlib
|
||||
admin@example:/config/container/ntpd/volume/varlib/> set target /var/lib
|
||||
admin@example:/config/container/ntpd/volume/varlib/> leave
|
||||
admin@example:/> copy running-config startup-config
|
||||
|
||||
The `ntp.conf` file is stored in the host's `startup-config` and any
|
||||
state data in the container's `/var/lib` is retained between reboots
|
||||
and across image upgrades.
|
||||
|
||||
|
||||
Upgrading a Container Image
|
||||
---------------------------
|
||||
Advanced
|
||||
--------
|
||||
|
||||
All container configurations are locked to the image hash at the time of
|
||||
first download, not just ones that use an `:edge` or `:latest` tag. An
|
||||
upgrade of containers using versioned images is more obvious -- update
|
||||
the configuration -- but the latter is a bit trickier. Either remove
|
||||
the configuration and recreate it (leave/apply the changes between), or
|
||||
use the admin-exec level command:
|
||||
This section covers advanced, and sometimes dangerous, topics. Please
|
||||
read any warnings and always consider the security aspects.
|
||||
|
||||
admin@example-c0-ff-ee:/> container upgrade NAME
|
||||
### Running Host Commands From Container
|
||||
|
||||
Where `NAME` is the name of your container. This command stops your
|
||||
container, does a `container pull IMAGE`, and then recreates the
|
||||
container with the new image. Upgraded containers are not automatically
|
||||
restarted.
|
||||
SSH login with keys is very handy, both remote scripting friendly *and
|
||||
secure*, but it does require a few extra configuration steps. The way
|
||||
to set it up is covered in part in [SSH Authorized Key][4].
|
||||
|
||||
admin@example-c0-ff-ee:/> container start NAME
|
||||
Another *insecure* approach is to access the host system directly,
|
||||
bypassing the namespaces that make up the boundary between host and
|
||||
container.
|
||||
|
||||
> **Note:** the default writable layer is lost when upgrading the image
|
||||
> Use named volumes for directories with writable content you wish to
|
||||
> keep over an upgrade.
|
||||
> **Security:** Please note, this completely demolishes the isolation
|
||||
> barrier between container and host operating system. It is only
|
||||
> suitable in situations where the container serves more as a unit of
|
||||
> distribution rather than as a separate component of the system.
|
||||
> *Strongly recommended* to use this only in trusted setups! Consider
|
||||
> also limiting the time frame in which this is active!
|
||||
|
||||
First, enable *Privileged* mode, this unlocks the door and allows the
|
||||
container to manage resources on the host system. An example is the
|
||||
`nftables` container mentioned previously.
|
||||
|
||||
admin@example:/config/container/system/> set privileged
|
||||
|
||||
Second, mount the host's `/proc/1` directory to somewhere inside your
|
||||
container. Here we pick `/1`:
|
||||
|
||||
admin@example:/config/container/system/> edit mount host
|
||||
admin@example:/config/container/system/mount/host/> set source /proc/1
|
||||
admin@example:/config/container/system/mount/host/> set target /1
|
||||
admin@example:/config/container/system/mount/host/> leave
|
||||
|
||||
Third, from inside the container, use the host's PID 1 namespaces with
|
||||
the `nsenter`[^2] command to slide through the container's walls. Here
|
||||
we show two example calls to `hostname`, first the container's own name
|
||||
and then asking what the hostname is on the host:
|
||||
|
||||
root@sys101:/# hostname
|
||||
sys101
|
||||
root@sys101:/# nsenter -m/1/ns/mnt -u/1/ns/uts -i/1/ns/ipc -n/1/ns/net hostname
|
||||
example
|
||||
|
||||
One use-case for this method is when extending Infix with a management
|
||||
container that connects to other systems. For some tips on how to
|
||||
control an Infix system this way, see [Scripting Infix](scriptiong.md).
|
||||
|
||||
[^2]: The `nsenter` program is available from either the util-linux
|
||||
package in Debian/Ubuntu/Mint, or in BusyBox. Note, however,
|
||||
it may not be enabled by default in BusyBox.
|
||||
|
||||
|
||||
[0]: networking.md
|
||||
[1]: https://github.com/kernelkit/infix/blob/main/src/confd/yang/infix-containers%402023-12-14.yang
|
||||
[2]: https://github.com/troglobit/mg
|
||||
[3]: https://github.com/opencontainers/image-spec/blob/main/image-layout.md
|
||||
[4]: system.md#ssh-authorized-key
|
||||
[5]: https://docs.docker.com/build/exporters/oci-docker/
|
||||
[6]: https://man7.org/linux/man-pages/man7/capabilities.7.html
|
||||
[podman]: https://podman.io
|
||||
|
||||
@@ -69,6 +69,13 @@ $ sudo apt install bc binutils build-essential bzip2 cpio \
|
||||
python rsync sed tar unzip wget
|
||||
```
|
||||
|
||||
For testing, a few more tools and services are required on your system:
|
||||
|
||||
```bash
|
||||
$ sudo apt install jq graphviz qemu-system-x86 qemu-system-arm \
|
||||
ethtool gdb-multiarch tcpdump tshark
|
||||
```
|
||||
|
||||
> For details, see the Getting Started and System Requirements sections
|
||||
> of the [excellent manual][1].
|
||||
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
# YANG to Ethtool Mapping
|
||||
|
||||
This column contains the mapping between YANG and Linux / Ethtool counters.
|
||||
|
||||
```
|
||||
|
||||
+25
-11
@@ -1,10 +1,13 @@
|
||||
# Hardware information and status
|
||||
# Hardware Information and Status
|
||||
|
||||
The hardware infomation and status is handled by the YANG model [IETF hardware][ietf-hardware].
|
||||
with deviations and augmentations in _infix-hardware_.
|
||||
The hardware infomation and status is handled by the YANG model [IETF
|
||||
hardware][1], with deviations and augmentations in _infix-hardware_.
|
||||
|
||||
## USB Ports
|
||||
For infix to be able to control the USB port(s), a device tree modification is needed (see _alder.dtsi_ for full example).
|
||||
|
||||
For Infix to be able to control USB port(s), a device tree modification
|
||||
is needed (see _alder.dtsi_ for full example).
|
||||
|
||||
```
|
||||
chosen {
|
||||
infix {
|
||||
@@ -13,33 +16,44 @@ For infix to be able to control the USB port(s), a device tree modification is n
|
||||
};
|
||||
};
|
||||
```
|
||||
|
||||
Two USB ports are also exposed in QEMU for test purpose.
|
||||
|
||||
All USB ports in the system will be disabled during boot due to the file _board/common/rootfs/etc/modprobe.d/usbcore.conf_.
|
||||
If you not want Infix to controll the USB port(s), remove the file or manually enable the USB bus, here is an example:
|
||||
All USB ports in the system will be disabled during boot due to the file
|
||||
`board/common/rootfs/etc/modprobe.d/usbcore.conf`. If you do not want
|
||||
Infix to control USB port(s), remove the file or manually enable the USB
|
||||
bus, here is an example:
|
||||
|
||||
```
|
||||
# Enable the bus
|
||||
# Enable the bus
|
||||
echo 1 > /sys/bus/usb/devices/usb1/authorized
|
||||
```
|
||||
|
||||
And then enable sub-devices (e.g. USB memory)
|
||||
|
||||
```
|
||||
# Enable a device plugged into usb1
|
||||
echo 1 > /sys/bus/usb/devices/usb1/1-1/authorized
|
||||
```
|
||||
|
||||
### Current status
|
||||
|
||||
```
|
||||
admin@example:/> show hardware
|
||||
USB PORTS
|
||||
NAME STATE
|
||||
USB unlocked
|
||||
```
|
||||
An USB port can be in two states _unlocked_ and _locked_. When a port is locked,
|
||||
all connected devices will get power, but never authorized by Linux to use.
|
||||
|
||||
An USB port can be in two states _unlocked_ and _locked_. When a port is
|
||||
locked, all connected devices will get power, but never authorized by
|
||||
Linux to use.
|
||||
|
||||
### Configure USB port
|
||||
> **Note:** You can only configure an USB ports that exist in _show hardware_ in admin exec.
|
||||
|
||||
> **Note:** You can only configure USB ports known to the system. See
|
||||
> `show hardware` in admin-exec context. (Use `do` prefix in configure
|
||||
> context.)
|
||||
|
||||
```
|
||||
root@example:/> configure
|
||||
@@ -48,4 +62,4 @@ all connected devices will get power, but never authorized by Linux to use.
|
||||
root@example:/>
|
||||
```
|
||||
|
||||
[ietf-hardware]: https://www.rfc-editor.org/rfc/rfc8348.html
|
||||
[1]: https://www.rfc-editor.org/rfc/rfc8348.html
|
||||
|
||||
File diff suppressed because one or more lines are too long
|
After Width: | Height: | Size: 1.1 MiB |
@@ -0,0 +1,138 @@
|
||||
# Introduction
|
||||
|
||||
This document provides an introduction of key concepts, details how
|
||||
the system boots, including failure modes, and provides links to
|
||||
other documents for further study.
|
||||
|
||||
## CLI
|
||||
|
||||
The command line interface (CLI, see-ell-i) is the traditional way of
|
||||
interacting with single network equipment like switches and routers.
|
||||
Today users have come to expect more advanced graphical GUIs, like a web
|
||||
interface, to manage a device or NETCONF-based tools that allow for
|
||||
managing entire fleets of installed equipment.
|
||||
|
||||
Nevertheless, when it comes to initial deployment and debugging, it
|
||||
is very useful to know how to navigate and use the CLI.
|
||||
|
||||
> Proceed to the [CLI User Guide](cli/tutorial.md).
|
||||
|
||||
|
||||
## Key Concepts
|
||||
|
||||
The two modes in the CLI are the admin-exec and the configure context.
|
||||
|
||||
However, when logging in to the system, from the console port or SSH,
|
||||
you land in a standard UNIX shell, Bash. This is for advanced users
|
||||
and remote scripting purposes (production equipment). To enter the
|
||||
CLI type:
|
||||
|
||||
admin@example:~$ cli
|
||||
admin@example:/>
|
||||
|
||||
The prompt, constructed from your username and the device's hostname,
|
||||
changes slightly. You are now in the admin-exec context of the CLI.
|
||||
Here you can inspect system status and do operations to debug networking
|
||||
issues, e.g. ping. You can also enter configure context by typing:
|
||||
`configure` followed by commands to `set`, `edit`, apply changes using
|
||||
`leave`, or `abort` and return to admin-exec.
|
||||
|
||||
> The [CLI Introduction](cli/introduction.md) can be useful to skim
|
||||
> through at this point.
|
||||
|
||||
The system has several datastores (or files):
|
||||
|
||||
- `factory-config` consists of a set of default configurations, some
|
||||
static and others generated per-device, e.g., a unique hostname and
|
||||
number of ports/interfaces. This file is generated at boot.
|
||||
- `failure-config` is also generated at boot, from the same YANG models
|
||||
as `factory-config`, and holds the system *Fail Secure Mode*
|
||||
- `startup-config` is created from `factory-config` at boot if it does
|
||||
not exist. It is loaded as the system configuration on each boot.
|
||||
- `running-config` is what is actively running on the system. If no
|
||||
changes have been made since the system booted, it is the same as
|
||||
`startup-config`.
|
||||
- `candidate-config` is created from `running-config` when entering the
|
||||
configure context. Any changes made here can be discarded (`abort`,
|
||||
`rollback`) or committed (`commit`, `leave`) to `running-config`.
|
||||
|
||||
> See the [Branding & Releases](branding.md) for information on how
|
||||
> `factory-config` and `failure-config` can be adapted to different
|
||||
> customer requirements.
|
||||
|
||||
|
||||
## System Boot
|
||||
|
||||
After the system firmware (BIOS or and [boot loader](boot.md) start
|
||||
Linux the following happens. The various failure modes, e.g., missing
|
||||
password in VPD, are detailed later in this section.
|
||||
|
||||

|
||||
|
||||
1. Before mounting `/cfg` and `/var` partitions, hosting read-writable
|
||||
data like `startup-config` and container images, the system first
|
||||
checks if a factory reset has been requested by the user, if so it
|
||||
wipes the contents of these partitions
|
||||
2. Linux boots with a device tree which is used for detecting generic
|
||||
make and model of the device, e.g., number of interfaces. It may
|
||||
also reference an EEPROM with [Vital Product Data](vpd.md). That is
|
||||
where the base MAC address and per-device password hash is stored.
|
||||
(Generic builds use the same MAC address and password)
|
||||
3. On every boot the system's `factory-config` and `failure-config` are
|
||||
generated from the YANG[^1] models of the current firmware version.
|
||||
This ensures that a factory reset device can always boot, and that
|
||||
there is a working fail safe, or rather *fail secure*, mode
|
||||
4. On first power-on, and after a factory reset, the system does not
|
||||
have a `startup-config`, in which case `factory-config` is copied
|
||||
to `startup-config`
|
||||
5. Provided the integrity of the `startup-config` is OK, a system
|
||||
service loads and activates the configuration
|
||||
|
||||
### Failure Modes
|
||||
|
||||
So, what happens if any of the steps above fail?
|
||||
|
||||
**VPD Fail**
|
||||
|
||||
The per-device password cannot be read, or is corrupt, so the system
|
||||
`factory-config` and `failure-config` are not generated:
|
||||
|
||||
1. First boot, or after factory reset: `startup-config` cannot be
|
||||
created or loaded, and `failure-config` cannot be loaded. The
|
||||
system ends up in an unrecoverable state, i.e., **RMA[^2] Mode**
|
||||
2. The system has booted (at least) once with correct VPD and password
|
||||
and already has a `startup-config`. Provided the `startup-config`
|
||||
is OK (see below), it is loaded and system boots successfully
|
||||
|
||||
In both cases, external factory reset modes/button will not help, and
|
||||
in the second case will cause the device to fail on the next boot.
|
||||
|
||||
> The second case does not yet have any warning or event that can be
|
||||
> detected from the outside. This is planned for a later release.
|
||||
|
||||
**Broken startup-config**
|
||||
|
||||
If loading `startup-config` fails for some reason, e.g., invalid JSON
|
||||
syntax, failed validation against the system's YANG model, or a bug in
|
||||
the system's `confd` service, the *Fail Secure Mode* is triggered and
|
||||
`failure-config` is loaded (unless VPD Failure, see above).
|
||||
|
||||
*Fail Secure Mode* is a fail-safe mode provided for debugging the
|
||||
system. The default[^3] is isolated interfaces with communication only to
|
||||
the management CPU, SSH and console login using the device's factory
|
||||
reset password, IP connectivity only using IPv6 link-local, and device
|
||||
discovery protocols: LLDP, mDNS-SD. The login and shell prompt are set
|
||||
to `failure-c0-ff-ee`, the last three octets of the device's base MAC
|
||||
address.
|
||||
|
||||
[^1]: YANG is a modeling language from IETF, replacing that used for
|
||||
SNMP (MIB), used to describe the subsystems and properties of
|
||||
the system.
|
||||
[^2]: Return Merchandise Authorization (RMA), i.e., broken beyond repair
|
||||
by end-user and eligible for return to manufacturer.
|
||||
[^3]: Customer specific builds can define their own `failure-config`.
|
||||
It may be the same as `factory-config`, with the hostname set to
|
||||
`failure`, or a dedicated configuration that isolates interfaces, or
|
||||
even disables ports, to ensure that the device does not cause any
|
||||
security problems on the network. E.g., start forwarding traffic
|
||||
between previously isolated VLANs.
|
||||
+9
-9
@@ -6,8 +6,9 @@ them, as well as the build system with its helper scripts and tools, is
|
||||
from [Buildroot][1], which is distributed under the terms of the GNU
|
||||
General Public License (GPL). See the file COPYING for details.
|
||||
|
||||
Some files in Buildroot contain a different license statement. Those
|
||||
files are licensed under the license contained in the file itself.
|
||||
Some files in Buildroot may contain a different open source license
|
||||
statement. Those files are licensed under the license contained in the
|
||||
file itself.
|
||||
|
||||
Buildroot and Infix also bundle patch files, which are applied to the
|
||||
sources of the various packages. Those patches are not covered by the
|
||||
@@ -20,13 +21,12 @@ Infix releases include the license information covering all Open Source
|
||||
packages. This is extracted automatically at build time using the tool
|
||||
`make legal-info`. Any proprietary software built on top of Infix, or
|
||||
Buildroot, would need separate auditing to ensure it does not link with
|
||||
any GPL[^2] licensed library.
|
||||
any GPL[^1] licensed library.
|
||||
|
||||
[^2]: Infix image builds use GNU libc (GLIBC) which is covered by the
|
||||
[LGPL][8]. The LGPL *does allow* proprietary software, as long as
|
||||
said software is linking dynamically, [not statically][5], to GLIBC.
|
||||
[^1]: Infix image builds use GNU libc (GLIBC) which is covered by the
|
||||
[LGPL][3]. The LGPL *does allow* proprietary software, as long as
|
||||
said software is linking dynamically, [not statically][2], to GLIBC.
|
||||
|
||||
[1]: https://buildroot.org/
|
||||
[2]: https://www.sysrepo.org/
|
||||
[5]: https://lwn.net/Articles/117972/
|
||||
[8]: https://en.wikipedia.org/wiki/GNU_Lesser_General_Public_License
|
||||
[2]: https://lwn.net/Articles/117972/
|
||||
[3]: https://en.wikipedia.org/wiki/GNU_Lesser_General_Public_License
|
||||
|
||||
+73
-68
@@ -1,12 +1,16 @@
|
||||
# Linux Networking
|
||||
# Network Configuration
|
||||
|
||||
Infix aims to support all Linux Networking constructs. The YANG models
|
||||
used to describe the system are chosen to fit well and leverage the
|
||||
underlying Linux kernel's capabilities. The `ietf-interfaces.yang`
|
||||
model forms the base, extended with `ietf-ip.yang` and other layer-3
|
||||
underlying Linux kernel's capabilities. The [ietf-interfaces.yang][1]
|
||||
model forms the base, extended with [ietf-ip.yang][2] and other layer-3
|
||||
IETF models. The layer-2 bridge and aggregate models are defined by
|
||||
Infix to exploit the unique features not available in IEEE models.
|
||||
|
||||
> **Note:** when issuing `leave` to activate your changes, remember to
|
||||
> also save your settings, `copy running-config startup-config`. See
|
||||
> the [CLI Introduction](cli/introduction.md) for a background.
|
||||
|
||||
|
||||
## Interface LEGO®
|
||||
|
||||
@@ -66,7 +70,7 @@ admin@example:/config/> set interface eth1 bridge-port bridge br0
|
||||
admin@example:/config/> leave
|
||||
```
|
||||
|
||||
Here we add two ports to bridge `br0`: `eth0` and `eth1`.
|
||||
Here we add two ports to bridge `br0`: `eth0` and `eth1`.
|
||||
|
||||
> **Note:** Infix has many built-in helpers controlled by convention.
|
||||
> E.g., if you name your bridge `brN`, where `N` is a number, Infix sets
|
||||
@@ -126,10 +130,15 @@ VLAN ID of the interface, compared to *all* the VLAN IDs if you run
|
||||
`tcpdump` on the lower-layer interface.
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit interface eth0.20
|
||||
admin@example:/config/interface/eth0.20/> set vlan id 20
|
||||
admin@example:/config/interface/eth0.20/> set vlan lower-layer-if eth0
|
||||
admin@example:/config/interface/eth0.20/> show
|
||||
type vlan;
|
||||
vlan {
|
||||
tag-type c-vlan;
|
||||
id 20;
|
||||
lower-layer-if eth0;
|
||||
}
|
||||
admin@example:/config/interface/eth0.20/> leave
|
||||
```
|
||||
|
||||
@@ -137,7 +146,7 @@ The example below assumes bridge br0 is already created, see [VLAN
|
||||
Filtering Bridge](#vlan-filtering-bridge).
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit interface vlan10
|
||||
admin@example:/config/interface/vlan10/> set vlan id 10
|
||||
admin@example:/config/interface/vlan10/> set vlan lower-layer-if br0
|
||||
@@ -248,18 +257,18 @@ Multiple address assignment methods are available:
|
||||
|
||||
Both for *link-local* and *global auto-configuration*, it is possible
|
||||
to auto-configure using a random suffix instead of the interface
|
||||
identifier.
|
||||
identifier.
|
||||
|
||||
|
||||
### Examples
|
||||
|
||||

|
||||
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
ipv6 fe80::ff:fe00:0/64 (link-layer)
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
admin@example:/>
|
||||
@@ -292,36 +301,36 @@ default.
|
||||
+ }
|
||||
+}
|
||||
admin@example:/config/interface/eth0/ipv4/> leave
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
ipv4 169.254.1.3/16 (random)
|
||||
ipv4 10.0.1.1/24 (static)
|
||||
ipv6 fe80::ff:fe00:0/64 (link-layer)
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
admin@example:/>
|
||||
|
||||
As shown, the link-local IPv4 address is configured with `set autconf
|
||||
enabled true`. The resulting address (169.254.1.3/16) is of type
|
||||
*random* ([IETF ip-yang][ietf-ip-yang]).
|
||||
*random* ([ietf-ip.yang][2]).
|
||||
|
||||
#### Use of DHCP for IPv4 address assignment
|
||||
|
||||

|
||||
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit dhcp-client
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit dhcp-client
|
||||
admin@example:/config/dhcp-client/> set client-if eth0
|
||||
admin@example:/config/dhcp-client/> set enabled true
|
||||
admin@example:/config/dhcp-client/> leave
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
ipv4 10.1.2.100/24 (dhcp)
|
||||
ipv6 fe80::ff:fe00:0/64 (link-layer)
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
admin@example:/>
|
||||
@@ -340,9 +349,9 @@ admin@example:/config/> edit interface eth0 ipv6
|
||||
admin@example:/config/interface/eth0/ipv6/> set enabled false
|
||||
admin@example:/config/interface/eth0/ipv6/> leave
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
admin@example:/>
|
||||
@@ -356,12 +365,12 @@ admin@example:/>
|
||||
admin@example:/config/> edit interface eth0 ipv6
|
||||
admin@example:/config/interface/eth0/ipv6/> set address 2001:db8::1 prefix-length 64
|
||||
admin@example:/config/interface/eth0/ipv6/> leave
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
ipv6 2001:db8::1/64 (static)
|
||||
ipv6 fe80::ff:fe00:0/64 (link-layer)
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
admin@example:/>
|
||||
@@ -373,16 +382,15 @@ admin@example:/>
|
||||
Stateless address auto-configuration of global addresses is enabled by
|
||||
default. The address is formed by concatenating the network prefix
|
||||
advertised by the router (here 2001:db8:0:1::0/64) and the interface
|
||||
identifier. The resulting address is of type *link-layer*, as it
|
||||
is formed based on the interface identifier ([IETF
|
||||
ip-yang][ietf-ip-yang]).
|
||||
identifier. The resulting address is of type *link-layer*, as it is
|
||||
formed based on the interface identifier ([ietf-ip.yang][2]).
|
||||
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
ipv6 2001:db8:0:1:0:ff:fe00:0/64 (link-layer)
|
||||
ipv6 fe80::ff:fe00:0/64 (link-layer)
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
admin@example:/>
|
||||
@@ -394,11 +402,11 @@ below.
|
||||
admin@example:/config/> edit interface eth0 ipv6
|
||||
admin@example:/config/interface/eth0/ipv6/> set autoconf create-global-addresses false
|
||||
admin@example:/config/interface/eth0/ipv6/> leave
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
ipv6 fe80::ff:fe00:0/64 (link-layer)
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
admin@example:/>
|
||||
@@ -411,34 +419,35 @@ By default, the auto-configured link-local and global IPv6 addresses
|
||||
are formed from a link-identifier based on the MAC address.
|
||||
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
ipv6 2001:db8:0:1:0:ff:fe00:0/64 (link-layer)
|
||||
ipv6 fe80::ff:fe00:0/64 (link-layer)
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
admin@example:/>
|
||||
|
||||
To avoid revealing identity information in the IPv6 address, it is
|
||||
possible to specify use of a random identifier ([ietf-ip][ietf-ip-yang] YANG and [RFC8981][ietf-ipv6-privacy]).
|
||||
possible to specify use of a random identifier ([ietf-ip.yang][2] and
|
||||
[RFC8981][3]).
|
||||
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit interface eth0 ipv6
|
||||
admin@example:/config/interface/eth0/ipv6/> set autoconf create-temporary-addresses true
|
||||
admin@example:/config/interface/eth0/ipv6/> leave
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
ipv6 2001:db8:0:1:b705:8374:638e:74a8/64 (random)
|
||||
ipv6 fe80::ad3d:b274:885a:9ffb/64 (random)
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
admin@example:/>
|
||||
|
||||
Both the link-local address (fe80::) and the global address (2001:)
|
||||
have changed type to *random*.
|
||||
have changed type to *random*.
|
||||
|
||||
### IPv4 forwarding
|
||||
To be able to route (static or dynamic) on the interface it is
|
||||
@@ -488,9 +497,7 @@ Remember to enable [IPv4 forwarding](#IPv4-forwarding) for the interfaces.
|
||||
admin@example:/config/routing/control-plane-protocol/static/name/default/> leave
|
||||
admin@example:/>
|
||||
|
||||
> **Note:** The only name allowed for a control-plane-protocol is currently
|
||||
> *default*. Meaning, you can only have one instance per routing protocol.
|
||||
|
||||
> **Note:** You can only have one instance per routing protocol.
|
||||
|
||||
### IPv6 Static routes
|
||||
|
||||
@@ -500,22 +507,19 @@ Remember to enable [IPv4 forwarding](#IPv4-forwarding) for the interfaces.
|
||||
admin@example:/config/routing/control-plane-protocol/static/name/default/> leave
|
||||
admin@example:/>
|
||||
|
||||
> **Note:** The only name allowed for a control-plane-protocol is currently
|
||||
> *default*. Meaning, you can only have one instance per routing protocol.
|
||||
> **Note:** You can only have one instance per routing protocol.
|
||||
|
||||
### OSPFv2 Routing
|
||||
Infix supports OSPF dynamic routing for IPv4, i.e., OSPFv2.
|
||||
Remember to enable [IPv4 forwarding](#IPv4-forwarding) for the
|
||||
interfaces you want to run OSPFv2.
|
||||
interfaces you want to run OSPFv2.
|
||||
|
||||
admin@example:/config/> edit routing control-plane-protocol ospfv2 name default
|
||||
admin@example:/config/routing/control-plane-protocol/ospfv2/name/default/> set ospf area 0.0.0.0 interface e0 enabled true
|
||||
admin@example:/config/routing/control-plane-protocol/ospfv2/name/default/> leave
|
||||
admin@example:/>
|
||||
|
||||
> **Note:** The only instance name allowed for a
|
||||
> control-plane-protocol is currently *default*. Meaning, you can
|
||||
> only have one instance per routing protocol.
|
||||
> **Note:** You can only have one instance per routing protocol.
|
||||
|
||||
#### OSPF area types
|
||||
In addition to *regular* OSPF areas, area types *NSSA* and *Stub* are supported.
|
||||
@@ -545,8 +549,8 @@ OSPF interface settings are done in context of an OSFP area, e.g.,
|
||||
*area 0.0.0.0*. Available commands can be listed using the `?` mark.
|
||||
|
||||
admin@example:/config/routing/control-plane-protocol/ospfv2/name/default/> edit ospf area 0.0.0.0
|
||||
admin@example:/config/routing/control-plane-protocol/ospfv2/name/default/ospf/area/0.0.0.0/> edit interface e0
|
||||
admin@example:/config/routing/control-plane-protocol/ospfv2/name/default/ospf/area/0.0.0.0/interface/e0/> set ?
|
||||
admin@example:/config/routing/control-plane-protocol/ospfv2/name/default/ospf/area/0.0.0.0/> edit interface e0
|
||||
admin@example:/config/routing/control-plane-protocol/ospfv2/name/default/ospf/area/0.0.0.0/interface/e0/> set ?
|
||||
bfd BFD interface configuration.
|
||||
cost Interface's cost.
|
||||
dead-interval Interval after which a neighbor is declared down
|
||||
@@ -561,7 +565,7 @@ OSPF interface settings are done in context of an OSFP area, e.g.,
|
||||
For example, setting the OSPF *interface type* to *point-to-point* for
|
||||
an Ethernet interface can be done as follows.
|
||||
|
||||
admin@example:/config/routing/control-plane-protocol/ospfv2/name/default/ospf/area/0.0.0.0/interface/e0/> set interface-type point-to-point
|
||||
admin@example:/config/routing/control-plane-protocol/ospfv2/name/default/ospf/area/0.0.0.0/interface/e0/> set interface-type point-to-point
|
||||
admin@example:/config/routing/control-plane-protocol/ospfv2/name/default/ospf/area/0.0.0.0/interface/e0/>
|
||||
|
||||
|
||||
@@ -573,7 +577,7 @@ debugging the OSPFv2 setup. The CLI has various OSPF status commands
|
||||
such as `show ospf neighbor`, `show ospf interface` and `show ospf
|
||||
routes`.
|
||||
|
||||
admin@example:/> show ospf neighbor
|
||||
admin@example:/> show ospf neighbor
|
||||
|
||||
Neighbor ID Pri State Up Time Dead Time Address Interface RXmtL RqstL DBsmL
|
||||
10.1.1.2 1 Full/- 3h46m59s 30.177s 10.1.1.2 e0:10.1.1.1 0 0 0
|
||||
@@ -622,10 +626,11 @@ The source protocol describes the origin of the route.
|
||||
The YANG model *ietf-routing* support multiple ribs but only two are
|
||||
currently supported, namely `ipv4` and `ipv6`.
|
||||
|
||||
[ietf-ip-yang]: https://www.rfc-editor.org/rfc/rfc8344.html
|
||||
[ietf-ipv6-privacy]: https://www.rfc-editor.org/rfc/rfc8981.html
|
||||
[1]: https://www.rfc-editor.org/rfc/rfc8343
|
||||
[2]: https://www.rfc-editor.org/rfc/rfc8344
|
||||
[3]: https://www.rfc-editor.org/rfc/rfc8981
|
||||
|
||||
[^1]: Please note, link aggregates are not yet supported in Infix.
|
||||
[^2]: Link-local IPv6 addresses are implicitly enabled when enabling IPv6.
|
||||
IPv6 can be enabled/disabled per interface in the [ietf-ip][ietf-ip-yang]
|
||||
YANG model.
|
||||
[^2]: Link-local IPv6 addresses are implicitly enabled when enabling
|
||||
IPv6. IPv6 can be enabled/disabled per interface in the
|
||||
[ietf-ip][2] YANG model.
|
||||
|
||||
+80
@@ -0,0 +1,80 @@
|
||||
Quality of Service
|
||||
==================
|
||||
|
||||
On occasion, most networks will experience congestion due to some
|
||||
extraordinary load being placed upon it. If the load is transient,
|
||||
switches and routers may be able to absorb such bursts of traffic by
|
||||
queuing packets in internal memories. However, if the load is
|
||||
sustained over long periods of time, queues will fill up and packets
|
||||
will start to be dropped. When such situations arise, it is the job of
|
||||
the network's Quality of Service (QoS) policy to define _which_
|
||||
packets to drop and which ones to prioritize, such that critical
|
||||
services remain operational.
|
||||
|
||||
|
||||
## Software Forwarded Traffic
|
||||
|
||||
For packets which are processed by a CPU, i.e. typically routed
|
||||
traffic, and bridged traffic between interfaces that do not belong to
|
||||
the same hardware switching domain, an [nftables container][1] can be
|
||||
used to define a QoS policy.
|
||||
|
||||
|
||||
## Hardware Forwarded Traffic
|
||||
|
||||
The default QoS policy for flows which are offloaded to a switching
|
||||
ASIC is defined by the hardware defaults of the device in question.
|
||||
|
||||
|
||||
### Marvell LinkStreet
|
||||
|
||||
This family of devices, sometimes also referred to as _SOHO_, are
|
||||
managed by the `mv88e6xxx` driver in the Linux kernel. While older
|
||||
chips in this family where limited to 4 output queues per port, this
|
||||
documentation is _only_ valid for newer generations with 8 output
|
||||
queues per port.
|
||||
|
||||
#### Default Policy
|
||||
|
||||
##### Queueing
|
||||
|
||||
Both layer 2 ([VLAN PCP][2]) and layer 3 ([IP DSCP][3]) priority marks
|
||||
are considered when selecting the output queue of an incoming
|
||||
frame. PCP to queue mapping is done 1:1. For IP packets, the 3 most
|
||||
significant bits of the DSCP is used to select the queue:
|
||||
|
||||
| PCP | DSCP | ⇒ | Queue | Weight |
|
||||
|----:|------:|---|------:|-------:|
|
||||
| 0 | 0-7 | ⇒ | 0 | 1 |
|
||||
| 1 | 8-15 | ⇒ | 1 | 2 |
|
||||
| 2 | 16-23 | ⇒ | 2 | 3 |
|
||||
| 3 | 24-31 | ⇒ | 3 | 6 |
|
||||
| 4 | 32-39 | ⇒ | 4 | 12 |
|
||||
| 5 | 40-47 | ⇒ | 5 | 17 |
|
||||
| 6 | 48-55 | ⇒ | 6 | 25 |
|
||||
| 7 | 56-63 | ⇒ | 7 | 33 |
|
||||
|
||||
For packets containing both a VLAN tag and an IP header, DSCP priority
|
||||
takes precedence over PCP priority. In cases where neither are
|
||||
available, packets are always assigned to queue 0.
|
||||
|
||||
Each port's set of 8 egress queues operate on a Weighted Round Robin
|
||||
([WRR][4]) schedule, using the weights listed in the table above. The
|
||||
sum of all weights adds up to 99, meaning that the weight of any given
|
||||
queue is roughly equivalent to the percentage of the available
|
||||
bandwidth reserved for it.
|
||||
|
||||
##### Marking
|
||||
|
||||
Any priority marks available on ingress are left unmodified when the
|
||||
frame egresses an output port. In the case when an IP packet ingresses
|
||||
_without_ a VLAN tag, and is to egress _with_ a VLAN tag, its PCP is
|
||||
set to the 3 most significant bits of it. If no priority information
|
||||
is available in the frame on ingress (i.e. untagged non-IP), then
|
||||
packets will egress out of tagged ports with PCP set to 0.
|
||||
|
||||
|
||||
[1]: container.md#application-container-nftables
|
||||
[2]: https://en.wikipedia.org/wiki/IEEE_802.1Q
|
||||
[3]: https://en.wikipedia.org/wiki/Differentiated_services
|
||||
[4]: https://en.wikipedia.org/wiki/Weighted_round_robin
|
||||
@@ -0,0 +1,336 @@
|
||||
# Scripting Infix
|
||||
|
||||
In some situations a user cannot, or does not want to, use the NETCONF
|
||||
API for interacting with Infix. Examples include production tasks and
|
||||
simpler remote scripting jobs to one or more remote devices.
|
||||
|
||||
This document assumes you have the password for the `admin` user, and
|
||||
that you can connect to the device. Please see [Finding my Device][1]
|
||||
for help on locating it.
|
||||
|
||||
Furthermore, the example commands shown here that are execute from a PC
|
||||
to a remote device over SSH, use Linux/UNIX. With advances lately in
|
||||
both Windows and macOS, many of the user friendly tools previously only
|
||||
available in Linux are now available there too.
|
||||
|
||||
- The shell prompt for the PC laptop side:
|
||||
|
||||
```shell
|
||||
~$
|
||||
```
|
||||
|
||||
- The shell prompt when logged in to an Infix device:
|
||||
|
||||
```shell
|
||||
admin@example:~$
|
||||
```
|
||||
|
||||
> **Note:** the shell script commands used here are the raw variants
|
||||
> which the CLI usually wraps in a warm and snugly blanket. Meaning
|
||||
> they may change over time, while the CLI wrappers do *not*. That
|
||||
> being said, please let us know if you find any inconsistencies.
|
||||
|
||||
|
||||
## Tips
|
||||
|
||||
- Ensure the `admin` user does *not* have `clish` as login shell
|
||||
- Enable [SSH key authentication](system.md#ssh-authorized-key)
|
||||
- Deploy same SSH *public* key to many Infix devices
|
||||
- Secure your *private* SSH key using, e.g., `ssh-agent`
|
||||
|
||||
The `ssh-keygen` command, used to create the private/public key pair,
|
||||
asks for a passphrase and although this is *technically optional* it is
|
||||
highly recommended to set one. For ease of use, in particular when
|
||||
scripting, use `ssh-agent` to avoid retyping the passphrase for every
|
||||
command.
|
||||
|
||||
Useful links on SSH, keys, and using `ssh-agent`:
|
||||
|
||||
- https://en.wikipedia.org/wiki/Ssh-agent
|
||||
- https://www.cyberciti.biz/faq/how-to-use-ssh-agent-for-authentication-on-linux-unix/
|
||||
- https://goteleport.com/blog/how-to-use-ssh-agent-safely/
|
||||
|
||||
|
||||
## Admin User Not Authorized?
|
||||
|
||||
All system services and critical configuration files are owned by the
|
||||
locked-down `root` user. It is not possible to activate the `root` user
|
||||
account for remote logins. Instead, use `admin` user and the `sudo`
|
||||
command prefix.
|
||||
|
||||
Here we are logged in to an example device:
|
||||
|
||||
```
|
||||
admin@example:~$ cp /cfg/startup-config.cfg /cfg/backup-config.cfg
|
||||
cp: can't create '/cfg/backup-config.cfg': Permission denied
|
||||
admin@example:~$ sudo cp /cfg/startup-config.cfg /cfg/backup-config.cfg
|
||||
```
|
||||
|
||||
## Examples
|
||||
|
||||
The following example commands are run from the PC over SSH. The
|
||||
following is a *very brief* introduction.
|
||||
|
||||
The notation is `ssh username@address`, where address can be an IPv4 or
|
||||
IPv6 address, a DNS name, or an mDNS name, e.g. infix.local. In the
|
||||
case of IPv6: `address%interface`, where interface differs between
|
||||
operating systems. On Linux and macOS the interface name is used, but
|
||||
on Windows the interface index[^1] is used.
|
||||
|
||||
[^1]: Press Win-r to bring up the Run dialog, enter `cmd.exe` and press
|
||||
enter. Then type in `ipconfig /all` to list all interfaces, their
|
||||
status, as well as interface index.
|
||||
|
||||
**Logging in to a device**
|
||||
|
||||
```
|
||||
~$ ssh admin@fe80::ff:fe00:0%eth0
|
||||
The authenticity of host 'fe80::ff:fe00:0%eth0 (fe80::ff:fe00:0%eth0)' can't be established.
|
||||
ED25519 key fingerprint is SHA256:5/9mw64jhmYyD8MD+SwrsG3RXMBbP48pDe2T8bg14RQ.
|
||||
This key is not known by any other names
|
||||
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
|
||||
Warning: Permanently added 'fe80::ff:fe00:0%eth0' (ED25519) to the list of known hosts.
|
||||
admin@fe80::ff:fe00:0%eth0's password: *****
|
||||
.-------.
|
||||
| . . | Infix -- a Network Operating System
|
||||
|-. v .-| https://kernelkit.github.io
|
||||
'-'---'-'
|
||||
|
||||
Run the command 'cli' for interactive OAM
|
||||
```
|
||||
|
||||
**Executing a command on a device**
|
||||
|
||||
```
|
||||
~$ ssh admin@fe80::ff:fe00:0%eth0 echo hej
|
||||
admin@fe80::ff:fe00:0%eth0's password: *****
|
||||
hej
|
||||
```
|
||||
|
||||
**Made Easy**
|
||||
|
||||
Connecting to networked devices using IP addresses is the way many
|
||||
people are used to. The above example with IPv6 tend to scare off
|
||||
people, so for the rest of this document we'll use the mDNS name
|
||||
instead:
|
||||
|
||||
```
|
||||
~$ ssh admin@infix.local%eth0
|
||||
The authenticity of host 'infix.local%eth0 (infix.local%eth0)' can't be established.
|
||||
```
|
||||
|
||||
### Factory Reset
|
||||
|
||||
The command option `-y` disables any "are you sure?" interaction and
|
||||
immediately triggers a factory reset and reboot of the device. It is
|
||||
when the device boots up it erases all writable storage.
|
||||
|
||||
```
|
||||
~$ ssh admin@infix.local%eth0 factory -y
|
||||
admin@infix.local%eth0's password: *****
|
||||
```
|
||||
|
||||
### System Reboot
|
||||
|
||||
```
|
||||
~$ ssh admin@infix.local%eth0 reboot
|
||||
admin@infix.local%eth0's password: *****
|
||||
```
|
||||
|
||||
### Set Date and Time
|
||||
|
||||
Devices running Infix may have their system time completely off and this
|
||||
can cause problems for upgrading and when accessing the web interface
|
||||
over HTTPS (certificate validation looks at start and end dates).
|
||||
|
||||
To set the device's system time, *and* sync that with the RTC:
|
||||
use the PCs current time as argument:
|
||||
|
||||
```
|
||||
~$ ssh admin@infix.local%eth0 "sudo date -s '2024-03-20 18:14+01:00' && sudo hwclock -w -u"
|
||||
admin@infix.local%eth0's password: *****
|
||||
```
|
||||
|
||||
> The `-u` option ensures saving system time to the RTC in UTC time.
|
||||
|
||||
Verify that the change took:
|
||||
|
||||
```
|
||||
~$ ssh admin@infix.local%eth0 date
|
||||
admin@infix.local%eth0's password: *****
|
||||
Wed Mar 20 17:14:47 UTC 2024
|
||||
```
|
||||
|
||||
### Remote Control of Ethernet Ports
|
||||
|
||||
There are two ways to do it:
|
||||
|
||||
1. Change the configuration without saving it to `startup-config`
|
||||
2. Change the operational state
|
||||
|
||||
The first involves sending a NETCONF command/config in XML, the second
|
||||
we will cover here. We start by querying available interfaces (ports)
|
||||
on the remote system:
|
||||
|
||||
```
|
||||
~$ ssh admin@infix.local%qtap0 ip -br a
|
||||
admin@infix.local%qtap0's password:
|
||||
lo UP 127.0.0.1/8 ::1/128
|
||||
e0 UP fe80::ff:fe00:0/64
|
||||
e1 UP
|
||||
e2 UP
|
||||
e3 UP
|
||||
e4 UP
|
||||
e5 UP fe80::ff:fe00:5/64
|
||||
e6 UP fe80::ff:fe00:6/64
|
||||
e7 UP fe80::ff:fe00:7/64
|
||||
e8 UP fe80::ff:fe00:8/64
|
||||
e9 UP 192.168.2.200/24 fe80::ff:fe00:9/64
|
||||
br0 UP
|
||||
```
|
||||
|
||||
Here we see a loopback interface (lo), ten Ethernet ports (e0-e9) and a
|
||||
bridge (br0). From this quick glance we can guess that the ports e1-e4
|
||||
are bridged (you can verify this with the remote command `bridge link`)
|
||||
because they do not have a link-local IPv6 address.
|
||||
|
||||
I know it's port e6 that I want to take down:
|
||||
|
||||
```
|
||||
~$ ssh admin@infix.local%qtap0 ip link set e6 down
|
||||
admin@infix.local%qtap0's password:
|
||||
RTNETLINK answers: Operation not permitted
|
||||
~$ ssh admin@infix.local%qtap0 sudo ip link set e6 down
|
||||
admin@infix.local%qtap0's password:
|
||||
```
|
||||
|
||||
Changing the operational link state of a port is a privileged command,
|
||||
so we have to prefix our command with `sudo`.
|
||||
|
||||
Inspecting the link state again show the port is now down:
|
||||
|
||||
```
|
||||
~$ ssh admin@infix.local%qtap0 ip -br a
|
||||
admin@infix.local%qtap0's password:
|
||||
lo UP 127.0.0.1/8 ::1/128
|
||||
e0 UP fe80::ff:fe00:0/64
|
||||
e1 UP
|
||||
e2 UP
|
||||
e3 UP
|
||||
e4 UP
|
||||
e5 UP fe80::ff:fe00:5/64
|
||||
e6 DOWN
|
||||
e7 UP fe80::ff:fe00:7/64
|
||||
e8 UP fe80::ff:fe00:8/64
|
||||
e9 UP 192.168.2.200/24 fe80::ff:fe00:9/64
|
||||
br0 UP
|
||||
```
|
||||
|
||||
### Check Device's Network Connectivity
|
||||
|
||||
Say you want to perform a [System Upgrade][#system-uprgade] and it just
|
||||
doesn't work, then you might want to ensure the device actually can
|
||||
reach the upgrade server.
|
||||
|
||||
```
|
||||
~$ ssh admin@infix.local%eth0 ping -c 3 server.local
|
||||
admin@infix.local%qtap0's password: *****
|
||||
PING server.local (192.168.2.42) 56(84) bytes of data.
|
||||
64 bytes from server.local: icmp_seq=1 ttl=64 time=0.201 ms
|
||||
64 bytes from server.local: icmp_seq=2 ttl=64 time=0.432 ms
|
||||
64 bytes from server.local: icmp_seq=3 ttl=64 time=0.427 ms
|
||||
|
||||
--- server.local ping statistics ---
|
||||
3 packets transmitted, 3 received, 0% packet loss, time 2050ms
|
||||
rtt min/avg/max/mdev = 0.201/0.353/0.432/0.107 ms
|
||||
```
|
||||
|
||||
Here we get a reply, so whatever is the issue with the upgrade was
|
||||
not hiding behind a connectivity issue at least.
|
||||
|
||||
### System Upgrade
|
||||
|
||||
The underlying software that handles upgrades is called [RAUC][2]. To
|
||||
trigger an upgrade you (currently) need an FTP/TFTP or HTTP/HTTPS server
|
||||
where RAUC can fetch the upgrade from. In this example we use an FTP
|
||||
server to upgrade the currently inactive "slot":
|
||||
|
||||
```
|
||||
~$ ssh admin@infix.local%eth0 rauc install ftp://server.local/infix-aarch64-24.06.0.pkg
|
||||
admin@infix.local%eth0's password: *****
|
||||
installing
|
||||
0% Installing
|
||||
0% Determining slot states
|
||||
20% Determining slot states done.
|
||||
20% Checking bundle
|
||||
20% Verifying signature
|
||||
40% Verifying signature done.
|
||||
40% Checking bundle done.
|
||||
40% Checking manifest contents
|
||||
60% Checking manifest contents done.
|
||||
60% Determining target install group
|
||||
80% Determining target install group done.
|
||||
80% Updating slots
|
||||
80% Checking slot rootfs.1
|
||||
90% Checking slot rootfs.1 done.
|
||||
90% Copying image to rootfs.1
|
||||
99% Copying image to rootfs.1 done.
|
||||
99% Updating slots done.
|
||||
100% Installing done.
|
||||
idle
|
||||
Installing `ftp://server.local/infix-aarch64-24.06.0.pkg` succeeded
|
||||
~$
|
||||
```
|
||||
|
||||
The inactive slot is now marked active and will be used on the next
|
||||
boot. To upgrade the partition we booted from, we must first reboot.
|
||||
|
||||
For more information, see the [Boot Procedure][3] document.
|
||||
|
||||
**Alternative:**
|
||||
|
||||
If you know your device has sufficient storage, eMMC or RAM disk (check
|
||||
with the remote command `df -h`), you can also copy the `.pkg` file to
|
||||
the device instead of having to set up an FTP/TFTP or HTTP/HTTPS server.
|
||||
|
||||
Create an upload directory where `admin` has write permission:
|
||||
|
||||
```
|
||||
~$ ssh admin@infix.local%eth0 "sudo mkdir /var/tmp/upload; sudo chown admin /var/tmp/upload"
|
||||
admin@infix.local%eth0's password:
|
||||
```
|
||||
|
||||
Copy the file with secure copy, first we show the nasty IPv6 version of
|
||||
the command:
|
||||
|
||||
```
|
||||
~$ scp infix-aarch64-24.06.0.pkg admin@\[fe80::ff:fe00:0%eth0\]:/var/tmp/upload/
|
||||
admin@fe80::ff:fe00:0%eth0's password:
|
||||
infix-aarch64-24.06.0.pkg 100% 296 601.4KB/s 00:00
|
||||
```
|
||||
|
||||
And the upgrade command itself:
|
||||
|
||||
```
|
||||
~$ ssh admin@infix.local%eth0 rauc install /var/tmp/upload/infix-aarch64-24.06.0.pkg
|
||||
admin@infix.local%eth0's password: *****
|
||||
.
|
||||
.
|
||||
.
|
||||
```
|
||||
|
||||
Remember to remove the file from the upload directory when you are done,
|
||||
this can be done before or after the reboot to activate the upgrade. If
|
||||
you want to upgrade both "slots", then you can of course keep the file
|
||||
until you are done (provided the upload directory was created on
|
||||
persistent storage).
|
||||
|
||||
```
|
||||
~$ ssh admin@infix.local%eth0 rm /var/tmp/upload/infix-aarch64-24.06.0.pkg
|
||||
admin@infix.local%eth0's password: *****
|
||||
~$
|
||||
```
|
||||
|
||||
[1]: discovery.md
|
||||
[2]: https://rauc.io/
|
||||
[3]: boot.md#system-upgrade
|
||||
+139
@@ -0,0 +1,139 @@
|
||||
# System Configuration
|
||||
|
||||
System settings in Infix are provided by the [ietf-system][1] YANG
|
||||
model, augmented with Linux specific extensions in [infix-system][2],
|
||||
like Message of the Day (login message) and user login shell. More
|
||||
on this later on in this document.
|
||||
|
||||
For the sake of brevity, the hostname in the following examples has been
|
||||
shortened to `host`. The default hostname is composed from a product
|
||||
specific string followed by the last three octets of the system base MAC
|
||||
address, e.g., `switch-12-34-56`. An example of how to change the
|
||||
hostname is included below.
|
||||
|
||||
> **Note:** when issuing `leave` to activate your changes, remember to
|
||||
> also save your settings, `copy running-config startup-config`. See
|
||||
> the [CLI Introduction](cli/introduction.md) for a background.
|
||||
|
||||
|
||||
## Changing Password
|
||||
|
||||
User management, including passwords, SSH keys, remote authentication is
|
||||
available in the system authentication configuration context.
|
||||
|
||||
```
|
||||
admin@host:/config/> edit system authentication user admin
|
||||
admin@host:/config/system/authentication/user/admin/> change password
|
||||
New password:
|
||||
Retype password:
|
||||
admin@host:/config/system/authentication/user/admin/> leave
|
||||
```
|
||||
|
||||
The `change password` command starts an interactive dialogue that asks
|
||||
for the new password, with a confirmation, and then salts and encrypts
|
||||
the password with sha512crypt.
|
||||
|
||||
It is also possible to use the `set password ...` command. This allows
|
||||
setting an already hashed password. To manually hash a password, use
|
||||
the `do password encrypt` command. This launches the admin-exec command
|
||||
to hash, and optionally salt, your password. This encrypted string can
|
||||
then be used with `set password ...`.
|
||||
|
||||
> **Tip:** if you are having trouble thinking of a password, Infix has a
|
||||
> `password generate` command in admin-exec context which generates
|
||||
> random passwords using the UNIX command `pwgen`. Use the `do` prefix
|
||||
> when inside any configuration context to access admin-exec commands.
|
||||
|
||||
|
||||
### SSH Authorized Key
|
||||
|
||||
Logging in remotely with SSH is possible by adding a *public key* to a
|
||||
user. Here we add the authorized key to the admin user, multiple keys
|
||||
are supported.
|
||||
|
||||
With SSH keys in place it is possible to disable password login, just
|
||||
remember to verify SSH login and network connectivity before doing so.
|
||||
|
||||
```
|
||||
admin@host:/config/> edit system authentication user admin
|
||||
admin@host:/config/system/authentication/user/admin/> edit authorized-key example@host
|
||||
admin@host:/config/system/authentication/user/admin/authorized-key/example@host/> set algorithm ssh-rsa
|
||||
admin@host:/config/system/authentication/user/admin/authorized-key/example@host/> set key-data AAAAB3NzaC1yc2EAAAADAQABAAABgQC8iBL42yeMBioFay7lty1C4ZDTHcHyo739gc91rTTH8SKvAE4g8Rr97KOz/8PFtOObBrE9G21K7d6UBuPqmd0RUF2CkXXN/eN2PBSHJ50YprRFt/z/304bsBYkDdflKlPDjuSmZ/+OMp4pTsq0R0eNFlX9wcwxEzooIb7VPEdvWE7AYoBRUdf41u3KBHuvjGd1M6QYJtbFLQMMTiVe5IUfyVSZ1RCxEyAB9fR9CBhtVheTVsY3iG0fZc9eCEo89ErDgtGUTJK4Hxt5yCNwI88YaVmkE85cNtw8YwubWQL3/tGZHfbbQ0fynfB4kWNloyRHFr7E1kDxuX5+pbv26EqRdcOVGucNn7hnGU6C1+ejLWdBD7vgsoilFrEaBWF41elJEPKDzpszEijQ9gTrrWeYOQ+x++lvmOdssDu4KvGmj2K/MQTL2jJYrMJ7GDzsUu3XikChRL7zNfS2jYYQLzovboUCgqfPUsVba9hqeX3U67GsJo+hy5MG9RSry4+ucHs=
|
||||
admin@host:/config/system/authentication/user/admin/authorized-key/example@host/> show
|
||||
algorithm ssh-rsa;
|
||||
key-data AAAAB3NzaC1yc2EAAAADAQABAAABgQC8iBL42yeMBioFay7lty1C4ZDTHcHyo739gc91rTTH8SKvAE4g8Rr97KOz/8PFtOObBrE9G21K7d6UBuPqmd0RUF2CkXXN/eN2PBSHJ50YprRFt/z/304bsBYkDdflKlPDjuSmZ/+OMp4pTsq0R0eNFlX9wcwxEzooIb7VPEdvWE7AYoBRUdf41u3KBHuvjGd1M6QYJtbFLQMMTiVe5IUfyVSZ1RCxEyAB9fR9CBhtVheTVsY3iG0fZc9eCEo89ErDgtGUTJK4Hxt5yCNwI88YaVmkE85cNtw8YwubWQL3/tGZHfbbQ0fynfB4kWNloyRHFr7E1kDxuX5+pbv26EqRdcOVGucNn7hnGU6C1+ejLWdBD7vgsoilFrEaBWF41elJEPKDzpszEijQ9gTrrWeYOQ+x++lvmOdssDu4KvGmj2K/MQTL2jJYrMJ7GDzsUu3XikChRL7zNfS2jYYQLzovboUCgqfPUsVba9hqeX3U67GsJo+hy5MG9RSry4+ucHs=;
|
||||
admin@host:/config/system/authentication/user/admin/authorized-key/example@host/> leave
|
||||
```
|
||||
|
||||
> **Note:** the `ssh-keygen` program already base64 encodes the public
|
||||
> key data, so there is no need to use the `text-editor` command, `set`
|
||||
> does the job.
|
||||
|
||||
|
||||
## Changing Hostname
|
||||
|
||||
Notice how the hostname in the prompt does not change until the change
|
||||
is committed by issuing the `leave` command.
|
||||
|
||||
```
|
||||
admin@host:/config/> edit system
|
||||
admin@host:/config/system/> set hostname example
|
||||
admin@host:/config/system/> leave
|
||||
admin@example:/>
|
||||
```
|
||||
|
||||
The hostname is advertised over mDNS-SD in the `.local` domain. If
|
||||
another device already has claimed the `example.local` CNAME, in our
|
||||
case, mDNS will advertise a "uniqified" variant, usually suffixing with
|
||||
an index, e.g., `example-1.local`. Use an mDNS browser to scan for
|
||||
available devices on your LAN.
|
||||
|
||||
> **Note:** critical services like syslog, mDNS, LLDP, and similar that
|
||||
> advertise the hostname, are restarted when the hostname is changed.
|
||||
|
||||
|
||||
## Changing Login Banner
|
||||
|
||||
The `motd-banner` setting is an Infix augment and an example of a
|
||||
`binary` type setting that can be changed interactively with the
|
||||
built-in [`text-editor` command](cli/text-editor.md).
|
||||
|
||||
> **Tip:** see the next section for how to change the editor used
|
||||
> to something you may be more familiar with.
|
||||
|
||||
```
|
||||
admin@host:/config/> edit system
|
||||
admin@host:/config/system/> text-editor motd-banner
|
||||
admin@host:/config/system/> leave
|
||||
admin@host:/>
|
||||
```
|
||||
|
||||
Log out and log back in again to inspect the changes.
|
||||
|
||||
|
||||
## Changing the Editor
|
||||
|
||||
The system has three different built-in editors that can be used
|
||||
as the `text-editor` command:
|
||||
|
||||
- `emacs` (Micro Emacs)
|
||||
- `nano` (GNU Nano)
|
||||
- `vi` (Visual Editor)
|
||||
|
||||
To change the editor to GNU Nano:
|
||||
|
||||
```
|
||||
admin@host:/> configure
|
||||
admin@host:/config/> edit system
|
||||
admin@host:/config/system/> set text-editor nano
|
||||
admin@host:/config/system/> leave
|
||||
admin@host:/>
|
||||
```
|
||||
|
||||
> **Note:** as usual, configuration changes only take effect after
|
||||
> issuing the `leave` command. I.e., you must change the editor first,
|
||||
> and then re-enter configure context to use your editor of choice.
|
||||
|
||||
|
||||
[1]: https://www.rfc-editor.org/rfc/rfc7317
|
||||
[2]: https://github.com/kernelkit/infix/blob/main/src/confd/yang/infix-system%402024-02-29.yang
|
||||
+2
-2
@@ -1,5 +1,5 @@
|
||||
Testing
|
||||
=======
|
||||
Regression Testing with Infamy
|
||||
==============================
|
||||
|
||||
Infix comes with a test suite that is intended to provide end-to-end
|
||||
verification of supported features. Generally speaking, this means
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user